Skip to main content

Technical Architecture & Overview

Metasploitable 3 is Rapid7 intentionally vulnerable training environment, with a Windows 2008 and an Ubuntu 14.04 target full of exploitable services, weak credentials, and misconfigurations. Machines build from Packer templates, so users construct their own images rather than downloading prebuilt ones. The project is not archived but has not seen active feature work in recent years.

Targeted Technical Use Cases

Practicing network exploitation and post-exploitation against a Windows-domain-flavored target in an isolated lab.

Evaluation & Trade-offs

Core Strengths

  • +Realistic Windows services for AD-era attack practice.
  • +Reproducible builds from open templates.
  • +Backed by Rapid7 as a training resource.

Trade-Offs & Limitations

  • -Feature-frozen; software stack is old by design.
  • -Build process adds setup friction versus prebuilt images.

Defensive Security Application

Testing detection coverage for well-known Windows exploitation techniques in a controlled lab.

Frequently Asked Questions

What is Metasploitable 3?

Metasploitable 3 is Rapid7 intentionally vulnerable training environment, with a Windows 2008 and an Ubuntu 14.04 target full of exploitable services, weak credentials, and misconfigurations. Machines build from Packer templates, so users construct their own images rather than downloading prebuilt ones. The project is not archived but has not seen active feature work in recent years.

What is Metasploitable 3 used for?

Practicing network exploitation and post-exploitation against a Windows-domain-flavored target in an isolated lab.

What are the strengths of Metasploitable 3?
  • +Realistic Windows services for AD-era attack practice.
  • +Reproducible builds from open templates.
  • +Backed by Rapid7 as a training resource.
What are the limitations of Metasploitable 3?
  • +Feature-frozen; software stack is old by design.
  • +Build process adds setup friction versus prebuilt images.
How is Metasploitable 3 used defensively?

Testing detection coverage for well-known Windows exploitation techniques in a controlled lab.