How Payloads Work (Metasploit)
How Payloads Work Payload modules are stored in modules/payloads/{singles,stages,stagers}/<platform> . When the framework starts up, stages are combined with stagers to create a complete payload that you can use in exploits. Then, handlers are paired with payloads so the framework will know how to create sessions with a given communications mechanism. Payloads are given reference names that indicate all the pieces, like so: Staged payloads: <platform>/[arch]/<stage>/<stager> Single payloads: <platform>/[arch]/<single> This results in payloads like windows/x64/meterpreter/reverse_tcp . Breaking that down, the platform is windows , the architecture is x64 , the final stage we’re delivering is meterpreter , and the stager delivering it is reverse_tcp . Note that architecture is optional because in some cases it is either ...