Create a local firewall rule to allow the hosting of a webserver
Host the web server using HFS or python
In real redteam engagements don't drop a reverse shell or even the stage 1 payload. Start off with a stage zero payload that beacons and quietly enumerates to see if the target is heavily protected
whoami and hostname is very noisy
use $env:Username and ls env: instead
One way to protect an enterprise application is to expose it to the internet via a Azure Proxy, make everyone authenticate using Entra ID and use a whitelist for people allowed to use it