Metasploit
What it’s for
An exploitation framework with modules, payloads and post-exploitation tooling.
Where it shines
- Great for learning how exploitation fits together
- Quick, reliable exploitation of well-known issues
Where it falls down
- Heavily signatured and flagged by EDR
- Noisy — not subtle
My take
I reach for it very, very rarely. It’s great to learn on, but it’s noisy and flagged, so I’d rather do things manually where I can.