Rapid7 Releases Metasploit Framework 6.5
Rapid7 released Metasploit Framework 6.5 on July 30, adding 422 modules developed over two years, Malleable C2 profiles for current Meterpreter payloads, and an MCP server integration. Rapid7 documents HTTP(S) traffic shaping across Windows, Java, Python, PHP, and Linux Meterpreter payloads, while WindowsForum reports that the MCP service separates read-only AI tooling from higher-risk actions.
Rapid7 released Metasploit Framework 6.5 on July 30, introducing 422 new modules accumulated over two years and adding Malleable C2 support for current Meterpreter payloads. The release also adds an MCP, or Model Context Protocol, server intended to connect compatible AI clients with Metasploit data and workflows.
According to Rapid7's release post, Malleable C2 profiles can alter the shape of Meterpreter HTTP(S) traffic. The capability is available across current Windows, Java, Python, PHP, and Linux Meterpreter payloads. Operators select a profile on disk through the MALLEABLEC2 option; Rapid7 notes that staged payloads apply the configuration after the stage loads, while stageless payloads use it immediately.
MCP access and action controls
WindowsForum, citing Rapid7's announcement, reports that the new msfmcpd service exposes Metasploit context, including reconnaissance results, module metadata, sessions, and other framework data, to MCP-compatible clients such as Claude and Cursor. Its account describes 16 tools, with read-only operations separated from actions including module execution, session interaction, and writing to an active Meterpreter session.
WindowsForum further reports that four higher-consequence actions are disabled by default and require an operator to deliberately enable dangerous actions. That boundary is important for security teams testing AI-assisted operator workflows: a model that can retrieve module information and summarize an engagement has a materially different risk profile from one authorized to execute modules or interact with compromised sessions.
There is an implementation detail to verify. WindowsForum notes that Rapid7's MCP setup guide describes an eight-tool, read-only implementation and characterizes active actions as future functionality. Organizations evaluating Framework 6.5 should validate the MCP tools and action settings in their specific build rather than infer enabled capabilities from release coverage alone.
Defender implications
Malleable C2 support gives authorized penetration testers a way to make Meterpreter HTTP(S) communications resemble selected traffic profiles. Rapid7's example demonstrates a profile configured to emulate Amazon browsing. In comparable adversary-emulation environments, traffic shaping can reduce the usefulness of simple network signatures, increasing the value of behavioral detections, endpoint telemetry, proxy analysis, and correlation of unusual process and network activity.
The framework remains an open-source penetration-testing tool, so the additions are relevant to both red-team operations and defensive validation. Security engineering teams can use the release as a prompt to assess whether their controls distinguish between benign-looking HTTP(S) traffic and suspicious endpoint behavior, and whether AI-tool integrations preserve meaningful approval gates for actions that change a target environment.
Key Points
- 1Rapid7 added 422 modules and Malleable C2 support, expanding Metasploit capabilities relevant to authorized adversary emulation and detection validation.
- 2WindowsForum reports MCP action controls separate read-only AI context retrieval from module execution and session interaction, reducing accidental autonomous changes.
- 3Comparable traffic-shaping capabilities often shift defensive emphasis from static network signatures toward endpoint, behavioral, and cross-telemetry correlation.
Scoring Rationale
Metasploit is widely used for penetration testing and security validation, making the new payload and C2 capabilities operationally relevant to red and blue teams. The MCP integration is notable for practitioners evaluating AI-assisted security tooling, particularly because action authorization boundaries need careful validation.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
