logo

Adding Egress Brute Force to PowerShell Payloads

ID: d4a10d0f-de1f-519b-9ad7-4dd35e6b5404

STIX ID: report--d4a10d0f-de1f-519b-9ad7-4dd35e6b5404

Feed Name: Black Hills Infosec Blog

Date Published: 2016-09-19

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive summary:** This post demonstrates a simple offensive technique to bypass egress filtering by embedding a PowerShell loop that probes outbound ports until a reverse-shell connects, combined with an iptables one-liner on the listener to forward all incoming ports to a single handler (e.g., Metasploit, netcat, Powercat). The author provides PoC code, usage notes, and testing caveats (iptables REJECT/DROP and potential enterprise firewall differences).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.