MSF database code, gemified
Ruby Other
Switch branches/tags
v2.0.0 v1.3.0 v1.2.11 v1.2.10 v1.2.7 v1.2.6 v1.2.5 v1.2.4 v1.2.3 v1.2.2 v1.2.1 v1.2.0 v1.1.0 v1.0.1 v1.0.0 v1.0.0.pre.rails.pre.4.0 v1.0.0.pre.rails.pre.4.0b v1.0.0.pre.rails.pre.4.0a v0.61.1.exploit v0.61.0.exploit v0.60.1.exploit v0.60.0.exploit v0.59.5.exploit v0.59.4.exploit v0.59.3.exploit v0.59.2.exploit v0.59.0.compatible-encoders-and-nops v0.58.0.payload-reference-name v0.57.0.compatible-payloads v0.56.1.compatible-payloads v0.56.0.compatible-payloads v0.55.0.compatible-payloads v0.54.8.module-cache-construction v0.54.8.firefox-and-nodejs v0.54.7.firefox-and-nodejs v0.54.6.firefox-and-nodejs v0.54.5.compatible-payloads v0.54.4.zdi-authority v0.54.4.eager_load v0.54.4.compatible-payloads v0.54.3.zdi-authority v0.54.3.firefox-and-nodejs v0.54.3.eager_load v0.54.2.module-cache-construction v0.53.6.module-cache-construction v0.53.5.progress-bar v0.53.5.module-cache-construction v0.53.4.progress-bar v0.53.3.module-cache-construction v0.53.3.db-seed-idempotency v0.53.2.module-cache-construction v0.53.2.metasploit-framework-module-cache-prefetch-time v0.53.1.metasploit-framework-module-cache-prefetch-time v0.53.0.metasploit-framework-module-cache-prefetch-time v0.52.0.module-cache-construction v0.51.0.module-cache-construction v0.50.2.module-cache-construction v0.50.1.module-cache-construction v0.50.0.module-cache-construction v0.49.0.module-cache-construction v0.48.0.module-cache-construction v0.47.1.module-cache-construction v0.47.0.module-cache-construction v0.46.0.module-cache-construction v0.45.3.module-cache-construction v0.45.2.module-cache-construction v0.45.1.module-cache-construction v0.45.0.module-cache-construction v0.44.0.module-cache-construction v0.43.8.module-cache-construction v0.43.7.module-cache-construction v0.43.6.module-cache-construction v0.43.5.module-cache-construction v0.43.4.module-cache-construction v0.43.3.module-cache-construction v0.43.2.module-cache-construction v0.43.1.module-cache-construction v0.43.0.module-cache-construction v0.41.6.module-cache-construction v0.41.4.module-cache-construction v0.41.3.module-cache-construction v0.41.2.module-caching v0.41.1.module-caching v0.40.4.dalvik-python-architectures v0.40.4.cwe-authority v0.40.3.module-caching v0.40.2.module-caching v0.40.1.module-caching v0.37.0.module-caching v0.36.0.module-caching
Nothing to show
Latest commit 884b879 Jan 23, 2017 @msjenkins-r7 msjenkins-r7 Bump to 2.0.15
Failed to load latest commit information.
app Ensure valid port settings when adding a service to a host. Jan 17, 2017
bin Backport MetasploitDataModels::Search Jun 13, 2014
config updating the concern for IPAddr Nov 15, 2016
db/migrate add os_family column to host Dec 29, 2016
lib Bump to 2.0.15 Jan 23, 2017
script Make metasploit_data_models a Rails Engine Oct 17, 2012
spec Ensure valid port settings when adding a service to a host. Jan 17, 2017
.coveralls.yml Backport MetasploitDataModels::Search Jun 13, 2014
.gitignore Remove secrets.yml and add to .gitignore, lock gemfile Mar 11, 2016
.rspec Update .rspec to rspec 3 --init May 5, 2015
.travis.yml bump ruby Dec 29, 2016
.yardopts Backport MetasploitDataModels::Search Jun 13, 2014 Use metasploit-version May 6, 2015 Add running `rake yard` to CONTRIBUTING May 12, 2015
Gemfile fix deps May 13, 2016
LICENSE Update LICENSE Dec 21, 2012 Add a line to the README about engine requires Oct 2, 2014 Remove jruby from RELEASING May 26, 2015
Rakefile Use metasploit-yard Apr 23, 2015 Use metasploit-version May 6, 2015
console_db.yml Loading ActiveRecord in console Feb 1, 2012
metasploit_data_models.gemspec fix deps May 13, 2016

#MetasploitDataModels Build StatusCode ClimateCoverage StatusDependency StatusGem Version

The database layer for Metasploit


MetasploitDataModels exists to do several key things:

  1. Allow code sharing between Metasploit Framework (MSF) and the commercial versions of Metasploit (Community, Express, Pro -- usually referred to collectively as "Pro")

  2. Give developers a lightweight entry point to MSF's backend for use in developing tools that gather data intended for later use with Metasploit (e.g. specialized scanners).

  3. Make it easy to keep commercial stuff private while increasing the functionality of the open-source tools we provide to the community.



In a Rails application, MetasploitDataModels acts a Rails Engine and the models are available to application just as if they were defined under app/models. If your Rails appliation needs to modify the models, this can be done using ActiveSupport.on_load hooks in initializers. The block passed to on_load hook is evaluated in the context of the model class, so defining method and including modules will work just like reopeninng the class, but ActiveSupport.on_load ensures that the monkey patches will work after reloading in development mode. Each class has a different on_load name, which is just the class name converted to an underscored symbol, so Mdm::ApiKey runs the :mdm_api_key load hooks, etc.

# Gemfile
gem :metasploiit_data_models, :git => git://, :tag => 'v0.3.0'

# config/initializers/metasploit_data_models.rb
ActiveSupport.on_load(:mdm_api_key) do
  # Returns the String obfuscated token for display. Meant to avoid CSRF
  # api-key stealing attackes.
  def obfuscated_token
    token[0..3] + "****************************"

This gem's Rails::Engine is not required automatically. You'll need to also add the following to your config/application.rb:

require 'metasploit_data_models/engine'

Metasploit Framework

In Metasploit Framework, MetasploitDataModels::Engine is loaded, but the data models are only if the user wants to use the database.


In Metasploit Pro, MDM is loaded via the metasploit_data_models gem:

An MRI and JRuby implementation is generated for all substantial updates.

Developer Info


The gem includes a console based on Pry

Give it a path to a working MSF database.yml file for full ActiveRecord-based access to your data.

Note: "development" mode is hardcoded into the console currently.