Command Reference

Beacons

Sleep

sleep 60 50               ; Sleep 60 sec with 50% of jitter (Call back between 30 to 60 secs randomly)

Command Execution

Default

run [command]

powershell.exe

powershell-import [/path/to/your.ps1]       ; Running it from your localhost
powershell [cmdlet] [args]

powerpick (Using PS w/o powershell.exe)

powrepick [cmdlet] [args]

psinject (Using PS within another process)

psinject [PID] [x86|x64] [cmdlet] [args]

.NET

cmd.exe

Session Passing

Parent Process Modification

SMB Beacn

TCP Beacn

Credentials and Hashes

Mimikatz

DCSync

File Download

File Upload

Token Stealing

Kerberos Tickets

Screenshots

Keylogging / ClipboardTheft

Last updated