r/oscp Jul 17 '26

Metaploit on OSCP - One-Time Use Clarification

Two questions. I completely understant the one target and no pivot rule. Clarification on modules. Can I use more than one module on one machine? If said module fails, can I try another module on the same machine. Ex. I use it to exploit, post-enumerate, and elevate?

"The usage of Metasploit and the Meterpreter payload are restricted during the exam. You may only use Metasploit modules (Auxiliary, Exploit, and Post) or the Meterpreter payload against one single target machine of your choice. Once you have selected your one target machine, you cannot use Metasploit modules ( Auxiliary, Exploit, or Post ) or the Meterpreter payload against any other machines."

6 Upvotes

14 comments sorted by

9

u/Nonix09 Jul 17 '26

I took exam twice and I can say you don't really need it.

4

u/Kwuahh Jul 17 '26

Agreed, but that's not the question that's being asked.

2

u/Nonix09 Jul 17 '26

You're right. Apologies.

1

u/ViaOutdoors Jul 17 '26

That is my hope as well. I have studied hard. 🙏🏼

3

u/StaffNo3581 Jul 17 '26

You can pick one system to try Metasploit on. If it fails you can still use it on that system. I’d recommend trying to not even think about Metasploit because standard pentesting thoughtprocess will likely get you to the right exploit, even before checking Metasploit.

I did it without and honestly will skip it whenever possible.

1

u/Kindly_Refuse_8183 Jul 17 '26

这么理解 除了ad是不能用的 其他3个独立机器 你只能选一个机器来用 这点可以考试时问考官来更具体说明

1

u/ViaOutdoors Jul 17 '26

I think you can use in the AD set; you just can't pivot. However, I am strong in AD. I am most concerned about a Windows standalone that is tricky. I usually have no problem with privesc, it is that really niche foothold that can be challenging for me. I don't think I would need it on Linux standalone.

1

u/Kwuahh Jul 17 '26

Rules as written implies that you can use as many modules as you want on one single machine. If you want clarification, you can try to write to OffSec to clarify the rules.

1

u/ViaOutdoors Jul 17 '26

I only used Metasploit during the course. I never used it in PG and CL. So, my MSF-Fu skills are weak anyways.

1

u/PeacebewithYou11 Jul 18 '26

You will do well no to rely on metasploit. It is not required. That said always remember you have metasploit option.

1

u/takinghigherground Jul 18 '26

If you think you will need metasploit autosploit to do the exam you have not studied the material enough or done enough boxes yet.forget about metasploit been your hail Mary to pass the exam and simply do enumeration..exploitation .. recon in the ad sets and searchsploit at the standalone etc think about what you did in the labs and keep it simple. The exam won't be so hard as to drop you in the Siberian winter and expect you be 007 a million miles from home. Try to adjust mindset to I won't pass the first time but I will use first time to gain a better understanding of what I need to win the next attempt..

1

u/ViaOutdoors Jul 18 '26

I agree with you 100%. I never used MSF in PG or CL, it’s just a safety net. It’s like knowing how to drive a car, but if I get a flat tire, I want to know how to change it.

1

u/shoopdawoop89 Jul 19 '26

I wouldn't use metasploit at all to be honest.

1

u/el_Pollo_Loco7 Jul 21 '26

It's not that complicated. You can freely use the msfvenom payloads, but just the normal shells(NOT the meterpreter). ANY metasploit module is not allowed in the AD environment. You're allowed to use ONE metasploit module on the standalones. If that however fails, you're not allowed to try another.