
Build notturne dei comuni strumenti offensivi in C#, appena usciti dai rispettivi rami master, compilati e rilasciati in modalità CDI tramite pipeline di release di Azure DevOps.
# SharpCollection Build notturne dei comuni strumenti offensivi in C#, prelevati freschi dai rispettivi rami master, compilati e rilasciati in modalità CDI tramite le release pipeline di Azure DevOps. Manca il tuo strumento preferito? Sentiti libero di aprire una issue o di mandarmi un DM su X [@Flangvik](https://x.com/Flangvik) **Tieni presente che execute-assembly di Cobalt Strike accetta solo binari compilati con la configurazione "Any CPU".** # OpSec Dovrei distribuire alla cieca uno di questi binari durante engagement reali? **F*ck no**, controlla sempre qualsiasi cosa distribuisci su una macchina o rete client. Es. https://github.com/dnSpyEx/dnSpy **Distribuire ciecamente qualsiasi cosa da questo repo dovrebbe essere riservato ad ambienti di laboratorio, VM, HackTheBox, mappatura delle detection e così via.** # Azure DevOps? Ogni notte alle 03:00, la pipeline Azure DevOps controlla la presenza di nuovi commit sul ramo master di tutti i repository. I rami con modifiche vengono automaticamente recuperati e compilati con diversi target framework e architetture, prima di essere pubblicati in questo repo. La pipeline si trova qui: https://dev.azure.com/FlangvikDev/SharpRelease # Build disponibili > **Legenda:** :heavy_check_mark: = Compilato attivamente | :x: = Non compilato | :warning: = La pipeline esiste ma tutti i passaggi sono disabilitati > > Gli strumenti contrassegnati con `*` hanno note speciali — vedi le note a piè di pagina sotto la tabella. > > Alcuni strumenti hanno come target versioni specifiche del framework: Certify, KrbRelay, KrbRelayUp e ShadowSpray hanno come target **v4.7.2**. ADCollector ha come target **v4.6.1**. | Strumenti \ .NET Framework | NET 4.0 | NET 4.5 | NET 4.7 | | --------------- | --------------- | --------------- | --------------- | | ADCollector `¹` | :x: | :x: | :heavy_check_mark:| | ADCSPwn | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | ADFSDump | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | ADSearch | :x: | :x: | :heavy_check_mark: | | AtYourService `²` | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | BadAssMacros | :x: | :heavy_check_mark: | :heavy_check_mark: | | BetterSafetyKatz | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | Certify `³` | :x: | :x: | :heavy_check_mark: | | CheeseTools `⁴` | :x: | :x: | :heavy_check_mark: | | DeployPrinterNightmare | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | EDD | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | Evasor `²` | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | Farmer | :x: | :x: | :heavy_check_mark: | | ForgeCert | :x: | :heavy_check_mark: | :heavy_check_mark: | | GMSAPasswordReader | :x: | :x: | :heavy_check_mark: | | Group3r | :x: | :heavy_check_mark: | :heavy_check_mark:| | Grouper2 | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | Internal-Monologue | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | InveighZero | :warning: | :warning: | :warning:| | KrbRelay `³` | :x: | :x: | :heavy_check_mark:| | KrbRelayUp `³` | :x: | :x: | :heavy_check_mark:| | LockLess | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | Moriarty | :x: | :heavy_check_mark: | :heavy_check_mark: | | PassTheCert | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | PurpleSharp | :x: | :heavy_check_mark: | :heavy_check_mark: | | Rubeus | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | RunasCs | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SafetyKatz | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SauronEye | :x: | :x: | :heavy_check_mark:| | Scout `⁷` | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SearchOutlook | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpSCOM `³` | :x: | :x: | :heavy_check_mark: | | Seatbelt | :heavy_check_mark: | :x: | :heavy_check_mark: | | ShadowSpray `³` | :x: | :x: | :heavy_check_mark:| | Sharp-SMBExec | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpADWS | :x: | :x: | :heavy_check_mark: | | SharpAllowedToAct | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpAppLocker | :x: | :heavy_check_mark: | :heavy_check_mark: | | SharpBlock `⁵` | :heavy_check_mark: | :heavy_check_mark: | :x: | | SharpBypassUAC | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpChisel | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpChrome | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpChromium | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpCloud | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpCOM | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpCookieMonster | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpCrashEventLog | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpDir | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpDoor `⁶` | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpDPAPI | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpDump | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpEDRChecker | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpExec | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharPersist | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpFiles | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpFinder | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpGPOAbuse | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpHandler | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpHose | :x: | :heavy_check_mark: | :heavy_check_mark: | | SharpHound | :x: | :x: | :heavy_check_mark: | | SharpKatz | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpKiller | :x: | :heavy_check_mark: | :heavy_check_mark: | | SharpLaps | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpMapExec | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpMiniDump | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpMove | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpNamedPipePTH | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpNoPSExec | :x: | :x: | :heavy_check_mark:| | SharpPrinter | :x: | :heavy_check_mark: | :heavy_check_mark:| | SharpRDP | :x: | :heavy_check_mark: | :heavy_check_mark:| | SharpReg | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpSCCM | :x: | :x: | :heavy_check_mark:| | SharpSearch | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpSecDump | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpShares | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpSMBSpray | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SharpSphere | :x: | :heavy_check_mark: | :heavy_check_mark:| | SharpSpray | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpStay | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpSuccessor | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpSvc | :x: | :x: | :heavy_check_mark: | | SharpSystemTriggers `⁸` | :warning: | :warning: | :warning:| | SharpSniper | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpSQLPwn | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpTask | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpTokenFinder | :x: | :heavy_check_mark: | :heavy_check_mark:| | SharpUp | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpView | :x: | :heavy_check_mark: | :heavy_check_mark:| | SharpWMI | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpWebServer | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpWifiGrabber | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpWSUS | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | SharpZeroLogon | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | Shhmon | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | Snaffler | :x: |:heavy_check_mark:|:x:| | SpoolSample | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SqlClient | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | StandIn | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | StickyNotesExtract | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | SweetPotato | :x: | :heavy_check_mark: | :heavy_check_mark:| | ThreatCheck | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | ThunderFox |:heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | TruffleSnout | :x: | :heavy_check_mark: | :heavy_check_mark:| | TokenStomp | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | Watson | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | | winPEAS | :x: | :heavy_check_mark: | :heavy_check_mark: | | WMIReg | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark:| | Whisker | :x: | :x: | :heavy_check_mark:| ### Note a piè di pagina 1. **ADCollector** — Ha come target specificamente .NET Framework **v4.6.1** (mappato alla colonna NET 4.7) 2. **AtYourService, Evasor** — Nessuna build AnyCPU, solo piattaforme x64/x86 3. **Certify, KrbRelay, KrbRelayUp, ShadowSpray** — Hanno come target specificamente .NET Framework **v4.7.2** 4. **CheeseTools** — La pipeline esiste ma non ha mai avuto una build completata con successo 5. **SharpBlock** — Compila solo NET 4.0 e NET 4.5; i passaggi per NET 4.7 sono disabilitati. Nessuna build AnyCPU (solo x64/x86) 6. **SharpDoor** — Pubblica solo binari x64 (compilati tramite script PowerShell) 7. **Scout** — Il repository originale è stato rimosso. I binari inclusi sono obsoleti e non più mantenuti 8. **SharpSystemTriggers** — La pipeline è **in pausa**. I binari esistenti potrebbero essere obsoleti > **InveighZero** :warning: — La pipeline ha tutti i passaggi di build **disabilitati** ed è non funzionante. I binari esistenti nel repo provengono da build precedenti. # Fonti / Crediti I link per tutti questi fantastici strumenti sono qui sotto :)* [ADCollector](https://github.com/dev-2null/ADCollector) - Strumento C# per estrarre rapidamente informazioni preziose dall'ambiente Active Directory @dev-2null * [ADCSPwn](https://github.com/bats3c/ADCSPwn) - Strumento C# per elevare i privilegi in una rete Active Directory forzando l'autenticazione dagli account macchina e inoltrandola al servizio certificati. @bats3c * [ADSearch](https://github.com/tomcarver16/ADSearch) - Strumento C# per interrogare AD tramite il protocollo LDAP @tomcarver16 (Solo NET 4.7) * [ADFSDump](https://github.com/fireeye/ADFSDump) - Uno strumento C# per estrarre ogni genere di dati utili da AD FS. @FireEye * [AtYourService](https://github.com/mitchmoser/AtYourService) - Assembly .NET C# per l'enumerazione dei servizi @mitchmoser * [BadAssMacros](https://github.com/Flangvik/BadAssMacros) - Generatore automatico di macro dannose basato su C# @Flangvik * [BetterSafetyKatz](https://github.com/Flangvik/BetterSafetyKatz) - Fork di SafetyKatz che recupera dinamicamente l'ultima versione di Mimikatz, applica le firme di patching a runtime e carica Mimikatz in memoria tramite PE. @Flangvik * [Certify](https://github.com/GhostPack/Certify) - Strumento C# per enumerare e sfruttare le configurazioni errate in Active Directory Certificate Services (AD CS). @harmj0y @tifkin_ * [CheeseTools](https://github.com/klezVirus/CheeseTools) - Strumenti sviluppati in proprio per il movimento laterale/l'esecuzione di codice @klezVirus * [EDD]( https://github.com/FortyNorthSecurity/EDD) - Enumerate Domain Data è progettato per essere simile a PowerView ma in .NET @FortyNorthSecurity * [Evasor](https://github.com/cyberark/Evasor) - Uno strumento da usare nella fase di post-exploitation per valutare e aggirare gli AV @CyberArk * [Farmer](https://github.com/mdsecactivebreach/Farmer) - Raccoglie hash NetNTLM in un dominio Windows tramite un server WebDAV locale @domchell * [ForgeCert](https://github.com/GhostPack/ForgeCert) - Usa un certificato CA rubato + chiave privata per forgiare certificati per utenti arbitrari. @tifkin_ * [GMSAPasswordReader](https://github.com/rvazarkar/GMSAPasswordReader) - Legge il blob della password da un account GMSA. @rvazarkar * [DeployPrinterNightmare]( https://github.com/Flangvik/DeployPrinterNightmare) - Strumento C# per installare una stampante di rete condivisa sfruttando il bug PrinterNightmare per consentire ad altre macchine della rete una facile escalation dei privilegi @Flangvik * [Grouper2](https://github.com/l0ss/Grouper2) - Strumento C# per individuare configurazioni errate legate alla sicurezza in Active Directory Group Policy. @mikeloss * [Group3r](https://github.com/Group3r/Group3r) - Strumento C# per trovare vulnerabilità in AD Group Policy, ma fatto meglio di quanto facesse Grouper2. @mikeloss * [Internal-Monologue](https://github.com/eladshamir/Internal-Monologue) - Recupera gli hash NTLM senza toccare LSASS @elad_shamir * [KrbRelay](https://github.com/cube0x0/KrbRelay) - Framework C# per il relaying Kerberos @cube0x0 * [KrbRelayUp](https://github.com/Dec0ne/KrbRelayUp) - Escalation dei privilegi locale universale senza fix in ambienti di dominio Windows dove la firma LDAP non è applicata @dec0ne * [LockLess](https://github.com/GhostPack/LockLess) - Consente la copia di file bloccati. @GhostPack * [Moriarty](https://github.com/BC-SECURITY/Moriarty) - Enumera le KB mancanti, rileva varie vulnerabilità e suggerisce potenziali exploit per l'escalation dei privilegi in Windows * [PassTheCert](https://github.com/AlmondOffSec/PassTheCert) - Strumento proof-of-concept per autenticarsi a un server LDAP/S con un certificato tramite Schannel. @AlmondOffSec * [PurpleSharp](https://github.com/mvelazc0/PurpleSharp) - Strumento C# di simulazione degli avversari che esegue tecniche avversarie allo scopo di generare telemetria degli attacchi in ambienti Windows monitorati. @mvelazc0 * [Rubeus](https://github.com/GhostPack/Rubeus) - Toolkit C# per l'interazione diretta con Kerberos e i relativi abusi. @GhostPack * [RunasCs](https://github.com/antonioCoco/RunasCs) - Versione open in C# del runas.exe integrato di Windows. @splinter_code * [SafetyKatz](https://github.com/GhostPack/SafetyKatz) - Combinazione di una versione leggermente modificata del progetto Mimikatz di @gentilkiwi e del .NET PE Loader di @subTee. @GhostPack * [SauronEye](https://github.com/vivami/SauronEye) - Strumento di ricerca C# per trovare file specifici contenenti parole chiave specifiche (.doc, .docx, .xls, .xlsx). @_vivami * [Scout](https://github.com/jaredhaight/scout) - Un assembly .NET per eseguire ricognizione contro gli host di una rete. @jaredhaight (**Repo rimosso — i binari sono obsoleti**) * [SearchOutlook](https://github.com/RedLectroid/SearchOutlook) - Strumento C# per cercare parole chiave in un'istanza in esecuzione di Outlook @RedLectroid * [Seatbelt](https://github.com/GhostPack/Seatbelt) - Esegue una serie di "safety checks" di ricognizione dell'host orientati alla sicurezza. @GhostPack * [ShadowSpray](https://github.com/Dec0ne/ShadowSpray) - Uno strumento per distribuire Shadow Credentials sull'intero dominio nella speranza di abusare di DACL GenericWrite/GenericAll a lungo dimenticate su altri oggetti del dominio. * [Sharp-SMBExec](https://github.com/checkymander/Sharp-SMBExec) - Una conversione nativa in C# dello script PowerShell Invoke-SMBExec di Kevin Robertson @checkymander * [SharpADWS](https://github.com/wh0amitz/SharpADWS) - Ricognizione e sfruttamento di Active Directory per Red Team tramite Active Directory Web Services (ADWS). @wh0amitz * [SharpAllowedToAct](https://github.com/pkb1s/SharpAllowedToAct) - Implementazione C# del takeover di un oggetto computer tramite delega vincolata basata sulle risorse (msDS-AllowedToActOnBehalfOfOtherIdentity) @pkb1s * [SharpAppLocker](https://github.com/Flangvik/SharpAppLocker) - Porting C# del cmdlet PS Get-AppLockerPolicy con funzionalità estese @Flangvik * [SharpBlock](https://github.com/CCob/SharpBlock) - Un metodo per bypassare le DLL di proiezione attiva degli EDR impedendo l'esecuzione del punto di ingresso. @CCob * [SharpBypassUAC](https://github.com/FatRodzianko/SharpBypassUAC) - Strumento C# per bypass UAC @rodzianko * [SharpChisel](https://github.com/shantanu561993/SharpChisel) - Wrapper C# per Chisel. @shantanu561993 * [SharpChrome](https://github.com/GhostPack/SharpDPAPI) - Implementazione specifica per Chrome di SharpDPAPI in grado di decrittare/analizzare cookie e credenziali di accesso. @GhostPack * [SharpChromium](https://github.com/djhohnstein/SharpChromium) - Progetto C# per recuperare dati Chromium, come cookie, cronologia e credenziali salvate. @djhohnstein * [SharpCloud](https://github.com/chrismaddalena/SharpCloud) - Semplice strumento C# per verificare l'esistenza di file di credenziali relativi ad AWS, Microsoft Azure e Google Compute. @chrismaddalena * [SharpCOM](https://github.com/rvrsh3ll/SharpCOM) - Porting C# di Invoke-DCOM @424f424f * [SharpCookieMonster](https://github.com/m0rv4i/SharpCookieMonster) - Strumento C# per estrarre i cookie del browser @m0rv4i * [SharpCrashEventLog](https://github.com/slyd0g/SharpCrashEventLog) - Porting C# di LogServiceCrash @slyd0g @limbenjamin * [SharpDir](https://github.com/jnqpblc/SharpDir) - Strumento C# per cercare file sia in file system locali che remoti. @jnqpblc * [SharpDoor](https://github.com/infosecn1nja/SharpDoor) - Strumento C# per consentire più sessioni RDP (Remote Desktop) applicando una patch al file termsrv.dll. @infosecn1nja * [SharpDPAPI](https://github.com/GhostPack/SharpDPAPI) - Porting C# di alcune funzionalità DPAPI di Mimikatz. @GhostPack * [SharpDump](https://github.com/GhostPack/SharpDump) - SharpDump è un porting C# della funzionalità Out-Minidump.ps1 di PowerSploit. @GhostPack * [SharpEDRChecker](https://github.com/PwnDexter/SharpEDRChecker) - Strumento C# per verificare la presenza di prodotti difensivi noti come antivirus, EDR e strumenti di logging @PwnDexter * [SharPersist](https://github.com/fireeye/SharPersist) - Toolkit C# per la persistenza. * [SharpExec](https://github.com/anthemtotheego/SharpExec) - SharpExec è uno strumento C# di sicurezza offensiva progettato per facilitare il movimento laterale. @anthemtotheego * [SharpFiles](https://github.com/fullmetalcache/SharpFiles) - Strumento C# per cercare file in base all'output di SharpShares. @fullmetalcache * [SharpFinder](https://github.com/s0lst1c3/SharpFinder) - Cerca file che corrispondono a criteri specifici nelle condivisioni leggibili all'interno del dominio * [SharpGPOAbuse](https://github.com/FSecureLABS/SharpGPOAbuse) - SharpGPOAbuse è un'applicazione .NET scritta in C# che può essere usata per sfruttare i diritti di modifica di un utente su un oggetto Criteri di gruppo (GPO). @FSecureLABS * [SharpHandler](https://github.com/jfmaes/SharpHandler) - Strumento C# per rubare/duplicare handle di LSASS @Jean_Maes_1994 * [SharpHose](https://github.com/ustayready/SharpHose) - Strumento asincrono di password spraying in C# per ambienti Windows. @ustayready * [SharpHound](https://github.com/BloodHoundAD/SharpHound) - Versione C# 2022 dell'Ingestor di BloodHound 4.x. @BloodHoundAD * [SharpKatz](https://github.com/b4rtik/SharpKatz) - Porting C# PURO di funzionalità significative di MimiKatz come logonpasswords, dcsync, ecc. @b4rtik * [SharpKiller](https://github.com/S1lkys/SharpKiller) - Bypass AMSI permanente di @ZeroMemoryEx portato a .NET Framework 4.8 @S1lky_1337 * [SharpLaps](https://github.com/swisskyrepo/SharpLAPS) - Uno strumento C# per recuperare le password LAPS da LDAP @pentest_swissky * [SharpMapExec](https://github.com/cube0x0/SharpMapExec) - Versione C# dello strumento CrackMapExec di @byt3bl33d3r @cube0x0 * [SharpMiniDump](https://github.com/b4rtik/SharpMiniDump) - Strumento C# per creare un minidump del processo LSASS dalla memoria @b4rtik * [SharpNamedPipePTH](https://github.com/S3cur3Th1sSh1t/SharpNamedPipePTH) - Strumento C# per Pass-the-Hash su Named Pipes. @S3cur3Th1sSh1t * [SharpNoPSExec](https://github.com/juliourena/SharpNoPSExec) - Strumento C# che consente l'esecuzione di comandi senza file per il movimento laterale. @juliourena * [SharpMove](https://github.com/0xthirteen/SharpMove) - Strumento C# per eseguire tecniche di movimento laterale @0xthirteen * [SharpPrinter](https://github.com/rvrsh3ll/SharpPrinter) - Strumento C# per scoprire stampanti su una rete @424f424f * [SharpRDP](https://github.com/0xthirteen/SharpRDP) - Applicazione console C# basata sul protocollo Remote Desktop Protocol per l'esecuzione autenticata di comandi @0xthirteen * [SharpReg](https://github.com/jnqpblc/SharpReg) - Strumento C# per interagire con l'API del servizio Remote Registry. @jnqpblc * [SharpSecDump](https://github.com/G0ldenGunSec/SharpSecDump) - Porting C# della funzionalità di dump remoto di SAM + LSA Secrets di secretsdump.py di impacket @G0ldenGunSec * [SharpSCCM](https://github.com/Mayyhem/SharpSCCM) - Utilità C# per interagire con SCCM @_Mayyhem * [SharpSCOM](https://github.com/breakfix/SharpSCOM) - Strumento C# per lo sfruttamento di SCOM, inclusi takeover dell'agente e movimento laterale. @breakfix * [SharpSearch](https://github.com/djhohnstein/SharpSearch) - Strumento C# per cercare file che corrispondono a un pattern. @djhohnstein * [SharpSMBSpray](https://github.com/rvrsh3ll/SharpSMBSpray) - Strumento C# per il password spraying SMB. @424f424f * [SharpShares](https://github.com/djhohnstein/SharpShares) - Enumera tutte le condivisioni di rete nel dominio corrente. @djhohnstein * [SharpSphere](https://github.com/JamesCooteUK/SharpSphere) - SharpSphere C# ha la capacità di interagire con i sistemi operativi guest delle macchine virtuali gestite da vCenter. @jkcoote & @grzryc * [SharpSpray](https://github.com/jnqpblc/SharpSpray) - Strumento C# per eseguire un attacco di password spraying contro tutti gli utenti di un dominio tramite LDAP. @jnqpblc * [SharpStay](https://github.com/0xthirteen/SharpStay) - Progetto .NET per installare la persistenza. @0xthirteen * [SharpSuccessor](https://github.com/yourusername/SharpSuccessor) - Strumento C# per sfruttare la vulnerabilità di escalation dei privilegi BadSuccessor / dMSA * [SharpSvc](https://github.com/jnqpblc/SharpSvc) - Strumento C# per interagire con l'API SC Manager. @jnqpblc (Solo NET 4.7) * [SharpSystemTriggers](https://github.com/cube0x0/SharpSystemTriggers) - Raccolta C# di trigger di autenticazione remota per forzare le macchine Windows. @cube0x0 * [SharpSniper](https://github.com/HunnicCyber/SharpSniper) - SharpSniper è un semplice strumento per trovare l'indirizzo IP di questi utenti così da poter prendere di mira la loro macchina. @hunniccyber * [SharpSQLPwn](https://github.com/lefayjey/SharpSQLPwn) - Strumento C# per identificare e sfruttare le debolezze nelle istanze MSSQL in ambienti Active Directory. @lefayjey * [SharpTask](https://github.com/jnqpblc/SharpTask) - Strumento C# per interagire con l'API del servizio Utilità di pianificazione (Task Scheduler). @jnqpblc * [SharpTokenFinder](https://github.com/HuskyHacks/SharpTokenFinder) - Implementazione C# di TokenFinder. Ruba i token di accesso M365 dalle app desktop di Office * [SharpUp](https://github.com/GhostPack/SharpUp) - Porting C# di varie funzionalità di PowerUp. @GhostPack * [SharpView](https://github.com/tevora-threat/SharpView) - Implementazione C# di PowerView di harmj0y. @tevora-threat * [SharpWMI](https://github.com/GhostPack/SharpWMI) - Implementazione C# di varie funzionalità WMI. @GhostPack * [SharpWebServer](https://github.com/mgeeky/SharpWebServer) - Un semplice server HTTP & WebDAV orientato al Red Team scritto in C# con funzionalità di cattura degli hash Net-NTLM. @mariuszbit * [SharpWifiGrabber](https://github.com/r3nhat/SharpWifiGrabber) - Sharp Wifi Password Grabber recupera in chiaro le password Wi-Fi da tutti i profili WLAN salvati su una workstation. @r3n_hat * [SharpWSUS](https://github.com/nettitude/SharpWSUS) - Strumento C# per il movimento laterale tramite WSUS. @naborstudio * [SharpZeroLogon](https://github.com/nccgroup/nccfsas/tree/main/Tools/SharpZeroLogon) - Porting C# di CVE-2020-1472 , noto anche come Zerologon. @buffaloverflow * [Shhmon](https://github.com/matterpreter/Shhmon) - Neutralizzazione di Sysmon tramite scaricamento del driver. @Shhmon * [SpoolSample](https://github.com/leechristensen/SpoolSample) - Strumento C# per forzare gli host Windows ad autenticarsi verso altre macchine tramite l'interfaccia RPC MS-RPRN. @tifkin_ * [Snaffler](https://github.com/SnaffCon/Snaffler) - Strumento C# per pentester che aiuta a trovare caramelle deliziose. @l0ss and @Sh3r4 * [SqlClient](https://github.com/FortyNorthSecurity/SqlClient) - Client mssql C# .NET per accedere ai dati del database tramite beacon. @FortyNorthSecurity * [StandIn](https://github.com/FuzzySecurity/StandIn) - Piccolo toolkit post-compromissione AD basato su C#. @FuzzySec * [StickyNotesExtract](https://github.com/V1V1/SharpScribbles) - Strumento C# che estrae dati dal database delle Note rapide (Sticky Notes) di Windows. @V1V1 * [SweetPotato](https://github.com/CCob/SweetPotato) - Escalation dei privilegi da Local Service a SYSTEM da Windows 7 a Windows 10 / Server 2019. @CCob * [ThreatCheck](https://github.com/rasta-mouse/ThreatCheck) - Strumento C# per identificare i byte che Microsoft Defender / AMSI contrassegna come dannosi. @rasta-mouse * [ThunderFox](https://github.com/V1V1/SharpScribbles) - C# Recupera dati (contatti, email, cronologia, cookie e credenziali) da Thunderbird e Firefox. @V1V1 * [TruffleSnout](https://github.com/dsnezhkov/TruffleSnout) - Toolkit iterativo di discovery AD basato su C# per operatori offensivi. @dsnezhkov * [TokenStomp](https://github.com/MartinIngesen/TokenStomp) - Implementazione C# del difetto di rimozione dei privilegi dei token scoperto da @GabrielLandau / Elastic. @Mrtn9 * [Watson](https://github.com/rasta-mouse/Watson) - Enumera le KB mancanti e suggerisce exploit per utili vulnerabilità di escalation dei privilegi. @rasta-mouse * [winPEAS](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite) - PEASS - Privilege Escalation Awesome Scripts (winPEAS). @carlospolop * [WMIReg](https://github.com/airzero24/WMIReg) - PoC C# per interagire con hive del registro locali/remoti tramite WMI. @airzero24 * [Whisker](https://github.com/eladshamir/Whisker) - Whisker è uno strumento C# per impadronirsi degli account utente e computer di Active Directory manipolando il loro attributo msDS-KeyCredentialLink. @elad_shamir