Listeners
⚠️ ALWAYS start your listener BEFORE executing the shell on target!
Netcat Listeners
Socat Listeners
Use pwncat-cs for automatic shell stabilization, file upload/download, and persistence. It's the modern pentester's netcat!
Linux Shells
MOST RELIABLE Bash Shells
Requires bash compiled with /dev/tcp support (most distros have this)
CLASSIC Netcat Shells
PYTHON Python Shells
Other Languages
Windows Shells
POWERSHELL PowerShell Shells
CMD & Netcat Windows
Most PowerShell payloads get flagged by Defender. Use obfuscation tools like Invoke-Obfuscation, or generate payloads with msfvenom using encoding.
Web Shells
PHP Web Shells
Full shell: /usr/share/webshells/php/php-reverse-shell.php
ASPX / JSP Shells
Full shells in /usr/share/webshells/
MSFVenom Payloads
Linux Payloads
Windows Payloads
Web Payloads
meterpreter/reverse_tcp = staged (smaller, needs handler). meterpreter_reverse_tcp = stageless (larger, standalone). Use staged for size-limited exploits, stageless for reliability.
Shell Stabilization
Raw shells suck! No tab completion, no arrow keys, Ctrl+C kills your shell. Fix it:
Spawn a PTY (on target)
Background shell
Configure TTY (on YOUR machine)
Set environment (back in shell)
Get your size with stty -a on your machine
Alternative PTY Spawns
Shell Escape / Breakout
Stuck in a restricted shell (rbash, rzsh, rksh)? Here's how to break out:
Common Escapes
More Escapes
Check gtfobins.github.io for shell escapes, SUID/SUDO exploits, and file read/write bypasses for any binary!
Bind Shells
When reverse shells don't work (strict egress filtering), make the target listen and YOU connect:
Target Listeners
Attacker Connect
Anyone can connect! Use strong ports and close ASAP. Consider adding a password check in your payload.
Encrypted Shells
Evade IDS/IPS and content inspection with encrypted traffic:
OpenSSL Encrypted Shell
Ncat SSL Encrypted
Socat Encrypted (Full TTY!)
IDS/IPS can't inspect encrypted traffic. Using port 443 makes it look like normal HTTPS. Combine with DNS tunneling for ultimate stealth!