For the complete documentation index, see llms.txt. This page is also available as Markdown.

Metasploit step configuration

Scan application instances with Metasploit Framework.

You can scan your application instances and ingest results from Metasploit Framework.

Workflow descriptions

Orchestration/extraction workflows

Ingestion workflows

Custom Scan step settings for Metasploit scans in STO

Scanner settings

These settings are required for most scanners. For more information, go to the reference for the scanner integration you're setting up.

Product name

The scanner name. This is required for all Custom Scan steps.

Key

Value

Scan type

The target type to scan.

Key

Value

Policy type

The scan mode to use.

Key

Value

Product config name

Key

Value

Specify one of the following if you're setting up an orchestration scan.

Brute-force test a host for SSH weak ssh/pass:

Check HTTPS (443) for Heartbleed vulnerability:

Finds and applies Metaspoit module by CVE:

Target and variant

Instance scan settings

Ingestion file

Fail on Severity

Last updated

Was this helpful?