{"repo":"ivan-sincek/powershell-reverse-tcp","free":true,"listed":false,"github":"https://github.com/ivan-sincek/powershell-reverse-tcp","clone":"git clone https://github.com/ivan-sincek/powershell-reverse-tcp.git","description":"PowerShell scripts for communicating with a remote host.","language":"PowerShell","stars":300,"topics":["powershell","reverse-tcp","bind-tcp","reverse-shell","bind-shell","networking","ethical-hacking","security","offensive-security","red-team-engagement"],"license":"MIT","category":"security-tools","readme_excerpt":"PowerShell Reverse TCP PowerShell scripts for communicating with a remote host. Invoke-Expression Process Pipes The scripts have known signatures. You should consider obfuscating them. Tested with PowerShell v5.1.19041.2673 on Windows 10 Enterprise OS (64-bit). Made for educational purposes. I hope it will help! Table of Contents How to Run Obfuscate PowerShell Scripts PowerShell Encoded Command SecureString AMSI Bypass MS Word Integration Set Up a Listener Runtime How to Run Change the IP address and port number inside the scripts as necessary. Open PowerShell from \\\\src\\\\invoke expression\\\\original\\\\ or \\\\src\\\\process pipes\\\\original\\\\ and run the commands shown below. Set the execution policy: Run the script: Or, simply run the following command from either PowerShell or Command Prompt: Obfuscate PowerShell Scripts To bypass EDRs and other security mechanisms, try obfuscating the scripts as shown in the example below. Original PowerShell command: Obfuscated PowerShell command: Search the Internet for obfuscation tools such as Invoke-Obfuscation. PowerShell Encoded Command To generate a PowerShell encoded command from a PowerShell script, run the following PowerShell command: To decode a PowerShell encoded command, run the following PowerShell command: Use the one-liners below if you don't want to leave any artifacts behind during an offensive security engagement. \\[Reverse TCP - Invoke-Expression\\] To pass parameters to the PowerShell encoded command, run the following com","default_branch":null,"files":null,"tree":[],"storefront":"/r/ivan-sincek","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ivan-sincek/powershell-reverse-tcp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}