Group Purchasing
Group Purchasing

SEC580: Metasploit for Enterprise Penetration Testing

SEC580Offensive Operations
  • 12 Hours (Self-Paced)
Course authored by:
Jeff McJunkin
Jeff McJunkin
SEC580: Metasploit for Enterprise Penetration Testing
Course authored by:
Jeff McJunkin
Jeff McJunkin
  • 12 CPEs

    Apply your credits to renew your certifications

  • Self-paced

    Train at your own pace from wherever you are

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 10 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Leverage the Metasploit Framework to perform advanced, enterprise penetration testing, vulnerability assessments, and post-exploitation across modern networks and systems.

Course Overview

SEC580 empowers penetration testers and security professionals to harness the full capabilities of the Metasploit Framework for professional, enterprise-level assessments. Students will explore advanced exploitation, post-exploitation, and pivoting techniques, leveraging the power of Meterpreter, client-side attacks, and integration with tools like Empire, Cobalt Strike, and Living Off The Land binaries. In this Metasploit pentesting course, emphasis is placed on stealth, automation, antivirus evasion, and simulating real-world adversaries in enterprise environments. Through hands-on labs and realistic attack scenarios, this course helps participants extend beyond traditional usage of Metasploit and apply it in structured, effective, and compliant penetration testing methodologies.

Maximize Metasploit: Effective Testing & Exploitation Skills

Today’s enterprise environments face complex security challenges that demand more than vulnerability scans and checklist assessments. SEC580: Enterprise Penetration Testing was designed to equip professionals with the skills to simulate real-world adversaries by using one of the most powerful tools in offensive security — the Metasploit Framework.

Penetration testers often rely on Metasploit without fully understanding its depth. While many users are familiar with launching exploits or generating payloads, few explore its broader capabilities for automation, reconnaissance, pivoting, or integration with enterprise tools. This course changes that.

SEC580 delivers a comprehensive methodology for using Metasploit in professional penetration tests. You will go beyond basic exploits to perform in-depth post-exploitation, command and control, data collection, and evasion techniques. The course explores real-world tactics such as spear-phishing, antivirus evasion, and password harvesting, using tools and techniques modeled after advanced adversaries.

Through a highly immersive, hands-on environment, you’ll test modern enterprise defenses, simulate breaches, and execute stealthy attacks. Each lab reinforces core concepts, including session management, privilege escalation, and pivoting into segmented networks — all while integrating with other tools and custom scripting.

This course hits the ground running, with minimal introductory content to focus on the highest-rewarding topics. In return, you’ll receive one of the most detailed and practical courses on Metasploit ever offered, created by experienced practitioners who use these techniques daily in red team and pentesting engagements.

By the end of the metasploit course, you’ll confidently use Metasploit as more than just an exploitation framework — it will become your go-to platform for scalable, flexible, and stealthy enterprise assessments.

Author Statement

Metasploit is the most widely used free exploitation framework in the world, yet most practitioners use only a small portion of what it offers. In SEC580, I guide you through mastering the core 10% of Metasploit more effectively — while unlocking the other 90% of its hidden potential. Whether you're conducting red team exercises, meeting compliance obligations, or validating defenses, this course will show you how to wield Metasploit like a seasoned professional. You’ll learn how to automate tasks, chain exploits, evade detection, and integrate with other tools, transforming Metasploit from a basic launcher into a full-spectrum penetration testing platform.

- Jeff McJunkin

What You’ll Learn

  • Execute advanced Metasploit exploitation techniques
  • Perform post-exploitation reconnaissance and pivoting
  • Master Meterpreter's extensive feature set
  • Deploy stealthy anti-virus evasion methods
  • Conduct effective spear-phishing campaigns

Business Takeaways

  • Reduce costs with professional-grade open-source tools
  • Meet regulatory compliance requirements efficiently
  • Enhance vulnerability assessment capabilities
  • Improve security testing methodology
  • Strengthen enterprise security posture

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC580: Metasploit for Enterprise Penetration Testing.

Section 1Metasploit for Enterprise Penetration Testing - Part I

This first section provides foundational mastery of Metasploit Framework through hands-on exercises, covering Ruby foundations, exploitation techniques, Meterpreter capabilities, and domain compromise methods.

Topics covered

  • Metasploit Architecture
  • Msfconsole Interface
  • Testing Methodology
  • Automation Scripts
  • PowerShell Integration

Labs

  • Implementing Msfconsole logging
  • Executing Meterpreter scripts
  • Performing AV bypass techniques
  • Conducting client-side attacks
  • Integrating with scanning tools

Overview

Section 1 is focused on helping attendees master the most robust and widely used exploitation framework in cybersecurity. Students will learn to wield Metasploit in professional-grade penetration testing engagements and discover powerful features that are often overlooked.

You will explore the inner workings of Metasploit, from its architecture and interfaces to post-exploitation and reconnaissance modules. Through practical exercises, you'll build a strong foundation in the framework's capabilities and see how far Meterpreter and auxiliary modules can take your tests. You’ll also explore how to evade defenses and automate complex tasks using Meterpreter scripts and post modules.

Want to compromise an entire Windows domain from a single foothold? You'll learn how to do that too — shell is only the beginning.

Full Topic Details

  • Guided Overview of Metasploit's Architecture and Components
  • Deep Dive into the Msfconsole Interface, including Logging and Session Manipulation
  • Exploitation Strategies and Pitfalls
  • The Ultimate Payload: Meterpreter In-Depth
  • Using Metasploit in a Professional Testing Methodology
  • Meterpreter Script Automation for Efficiency and Consistency
  • Reconnaissance and Scanning with Metasploit
  • Auxiliary Modules and Their Power
  • Antivirus Evasion Techniques
  • Client-Side Exploits via One-Liner Payloads
  • Port and Vulnerability Scanning (Nmap, Nessus, Qualys Integration)
  • SMB Credential Capture and PowerShell Integration

Section 2Metasploit for Enterprise Penetration Testing - Part 2

Section two focuses on advanced attack techniques, including client-side attacks, pivoting, and integration with other penetration testing tools to model sophisticated threat actors.

Topics covered

  • Advanced Pivoting
  • Privilege Escalation
  • Windows Payload Management
  • Data Exfiltration
  • Tool Integration

Labs

  • Implementing pivoting techniques
  • Setting up SOCKS proxies
  • Executing privilege escalation
  • Customizing Meterpreter scripts
  • Deploying persistence mechanisms

Overview

Building on the foundations of Section 1, this section focuses on using Metasploit in tandem with other tools and advanced tactics to model the behavior of sophisticated attackers. You’ll perform client-side attacks, establish persistence, pivot into isolated network segments, and automate attacks through scripting and tool integration.

This section is highly focused on simulating modern, real-world threats. From phishing payloads to covert command and control infrastructure, you’ll practice building full kill chains that stress-test enterprise security postures. You’ll also examine forensic artifacts left behind and refine your techniques for stealth and persistence.

Full Lab Details

  • Pivoting and Routing via Compromised Hosts
  • Configuring and Using SOCKS Proxies
  • Escalating Privileges on Windows Targets
  • Customizing Meterpreter Scripts and Payloads
  • Building Persistence Mechanisms and Avoiding Detection

Full Topic Details

  • Pivoting through Exploited Systems with Routing and SOCKS Proxies
  • Windows and Linux Privilege Escalation Techniques
  • Integration with CrackMapExec and Third-Party Tools
  • Data Exfiltration and Post-Exploitation Data Gathering
  • Advanced Meterpreter Scripting and Customization
  • Client-Side Attacks using Spear-Phishing and Document Payloads
  • Stealth, Evasion, and Anti-Forensics
  • Persisting on Target Systems
  • Real-World Red Team Tradecraft Modeled in Labs
  • C2 Infrastructure Concepts and Alternative Payloads

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple systems using the M1/M2/M3 processor line cannot perform the necessary virtualization functionality and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 8GB of RAM or more is required.
  • 60GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

If you have additional questions about the laptop specifications, please contact customer service.

SEC580 training is recommended for a diverse range of individuals, including:

  • Penetration Testers
  • Security Consultants
  • Red Team Operators
  • Vulnerability Assessment Specialists
  • IT Security Engineers
  • Network Security Analysts
  • Security Researchers
  • Auditors
  • Blue Teamers and Incident Responders looking to understand attacker tools

  • Printed and digital course books
  • MP3 audio files of the entire course

There are no specific prerequisites required for SEC580 training. 

This SEC580 metasploit training course is part of the Offensive Operations focus area, which covers offensive security techniques and penetration testing. It is considered more specialized penetration testing training, and other courses that may complement this training include SEC556: IoT Penetration Testing.

Metasploit is more than just a toolkit—it’s a critical skillset for ethical hackers, red teamers, and defenders who need to understand how attackers operate.

Key Reasons Why This Training Matters:

  • Offensive Insight for Defensive Advantage: Knowing how exploits work in practice allows defenders to better secure their environments.
  • Enterprise-Grade Scenarios: SEC580 focuses on large-scale, complex environments, not just simple lab targets—this makes training directly applicable to real-world enterprise security operations.
  • Automation & Efficiency: Students learn to automate attacks and testing routines, saving time and improving coverage in engagements.
  • Bridges Knowledge Gaps: Even seasoned professionals benefit from learning Metasploit’s full capabilities, including scripting in Meterpreter and integrating with tools like PowerShell, Mimikatz, and more.

  • Master Metasploit: Go beyond the basics—build elite-level exploitation and automation skills trusted in top-tier pen testing roles
  • Stand Out Professionally: Gain credibility and recognition with advanced, enterprise-grade offensive security techniques
  • Boost Role Flexibility: Skills apply across red teaming, blue teaming, incident response, and security engineering
  • Earn a Premier Certification: Prepares you for the GIAC GXPN—a powerful career credential
  • Join the SANS Cyber Community: Access a global network of experts, mentorship, and continuous growth

Relevant Job Roles

Vulnerability Analysis (OPM 541)

NICE: Protection and Defense

Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities.

Explore learning path

Application Pen Tester

Offensive Operations

Application penetration testers probe the security integrity of a company’s applications and defenses by evaluating the attack surface of all in-scope vulnerable web-based services, clientside applications, servers-side processes, and more. Mimicking a malicious attacker, app pen testers work to bypass security barriers in order to gain access to sensitive information or enter a company’s internal systems through techniques such as pivoting or lateral movement.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $3,505 USD*Prices exclude applicable local taxes
    Registration Options
Showing 1 of 1

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources