Skip to main content

HTTP (TCP 80)

Python Web Server (Attacker)


PowerShell: Invoke-WebRequest

Execute in memory:

PowerShell: WebClient (Stealthier)


Certutil (CMD LOLBIN)


SMB (TCP 139 / 445)

Attacker


Victim Download

PowerShell:

Upload Loot


HTTPS (TCP 443)

Attacker

Victim


Netcat Raw Transfer (TCP 4444)

Upload to victim (push)

Attacker:
Victim:

Download from victim (exfil)

Attacker:
Victim:

Base64 Transfer (AV Evasion / Restricted Shell)

Attacker

Serve:

Victim