Files
Angerona/documentation-payload/Cazalla/commands/rpfwd.md
T
marcos.luna 2fe9fa8254 wiki created
2025-11-06 12:23:49 +01:00

2.3 KiB

rpfwd - Reverse Port Forwarding

Start or stop reverse port forwarding (RPFWD).

Description

The rpfwd command starts or stops reverse port forwarding (RPFWD). When started, the agent listens on a local port on the target system. Connections to this local port are forwarded through the agent to Mythic, which then connects to a remote destination.

Syntax

rpfwd {"action":"start","port":8080,"remote_host":"127.0.0.1","remote_port":80}
rpfwd {"action":"stop","port":8080}

Parameters

  • action (required): Either "start" or "stop"
  • port (required for start): Local port on the agent to listen on (default: 8080)
  • remote_host (required for start): Remote host to forward connections to
  • remote_port (required for start): Remote port to forward connections to

Examples

rpfwd {"action":"start","port":8080,"remote_host":"192.168.1.100","remote_port":80}
rpfwd {"action":"start","port":3306,"remote_host":"10.0.0.50","remote_port":3306}
rpfwd {"action":"stop","port":8080}

Features

  • When started, the agent listens on a local port on the target system
  • Connections to this local port are forwarded through the agent to Mythic, which then connects to a remote destination (remote_host:remote_port)
  • Default local port: 8080
  • Useful for accessing services on the target network that are not directly reachable from Mythic (e.g., internal services, databases, management interfaces)
  • WARNING: Reverse port forwarding creates persistent network connections and may be detected by network monitoring, firewall logging, NIDS, and EDR/XDR network monitoring
  • Avoid using privileged ports (<1024) which require elevated privileges

Output

[rpfwd] Reverse port forwarding started on port 8080
[rpfwd] Forwarding connections to: 192.168.1.100:80

OPSEC Considerations

  • Reverse port forwarding creates persistent network connections
  • May be detected by network monitoring, firewall logging, NIDS, and EDR/XDR network monitoring
  • Avoid using privileged ports (<1024) which require elevated privileges
  • Consider the operational impact before starting

Reverse Port Forwarding Support, Usage Examples


Command Category: Network Tunneling
Requires Admin: No