Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
SharpCollection — Build notturne dei comuni strumenti offensivi in C#, appena usciti dai rispettivi rami master, compilati e rilasciati in modalità CDI tramite pipeline di release di Azure DevOps. | Kitploit
Strumenti/GitHubGitHub/flangvik/sharpcollection
Escalation di PrivilegiRicognizioneAttacchi alle PasswordExploitMovimento LateralePost-ExploitPenetration TestingRed TeamingRisorse Curate
GitHubflangvik/sharpcollection

SharpCollection

Build notturne dei comuni strumenti offensivi in C#, appena usciti dai rispettivi rami master, compilati e rilasciati in modalità CDI tramite pipeline di release di Azure DevOps.

2.9k395224 giorni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Vedi Repository
# SharpCollection
Build notturne dei comuni strumenti offensivi in C#, prelevati freschi dai rispettivi rami master, compilati e rilasciati in modalità CDI tramite le release pipeline di Azure DevOps.

Manca il tuo strumento preferito? Sentiti libero di aprire una issue o di mandarmi un DM su X [@Flangvik](https://x.com/Flangvik)
**Tieni presente che execute-assembly di Cobalt Strike accetta solo binari compilati con la configurazione "Any CPU".**

# OpSec

Dovrei distribuire alla cieca uno di questi binari durante engagement reali?
**F*ck no**, controlla sempre qualsiasi cosa distribuisci su una macchina o rete client. Es. https://github.com/dnSpyEx/dnSpy
**Distribuire ciecamente qualsiasi cosa da questo repo dovrebbe essere riservato ad ambienti di laboratorio, VM, HackTheBox, mappatura delle detection e così via.**

# Azure DevOps?
Ogni notte alle 03:00, la pipeline Azure DevOps controlla la presenza di nuovi commit sul ramo master di tutti i repository. I rami con modifiche vengono automaticamente recuperati e compilati con diversi target framework e architetture, prima di essere pubblicati in questo repo.

La pipeline si trova qui:
https://dev.azure.com/FlangvikDev/SharpRelease


# Build disponibili

> **Legenda:** :heavy_check_mark: = Compilato attivamente | :x: = Non compilato | :warning: = La pipeline esiste ma tutti i passaggi sono disabilitati
>
> Gli strumenti contrassegnati con `*` hanno note speciali — vedi le note a piè di pagina sotto la tabella.
>
> Alcuni strumenti hanno come target versioni specifiche del framework: Certify, KrbRelay, KrbRelayUp e ShadowSpray hanno come target **v4.7.2**. ADCollector ha come target **v4.6.1**.

| Strumenti \ .NET Framework | NET 4.0 |  NET 4.5 |  NET 4.7 |
| --------------- | --------------- | --------------- | --------------- |
| ADCollector `¹` | :x: | :x: |  :heavy_check_mark:|
| ADCSPwn | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| ADFSDump | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| ADSearch | :x: | :x: |  :heavy_check_mark: |
| AtYourService `²` | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| BadAssMacros | :x: | :heavy_check_mark: |  :heavy_check_mark: |
| BetterSafetyKatz | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| Certify `³` | :x: | :x: |  :heavy_check_mark: |
| CheeseTools `⁴` | :x: | :x: |  :heavy_check_mark: |
| DeployPrinterNightmare | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| EDD | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| Evasor `²` | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| Farmer | :x: | :x: |  :heavy_check_mark: |
| ForgeCert | :x: | :heavy_check_mark: |  :heavy_check_mark: |
| GMSAPasswordReader | :x: | :x: |  :heavy_check_mark: |
| Group3r | :x: | :heavy_check_mark: |  :heavy_check_mark:|
| Grouper2 | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| Internal-Monologue | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| InveighZero | :warning: | :warning: |  :warning:|
| KrbRelay `³` | :x: | :x: |  :heavy_check_mark:|
| KrbRelayUp `³` | :x: | :x: |  :heavy_check_mark:|
| LockLess | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| Moriarty | :x: | :heavy_check_mark: | :heavy_check_mark: |
| PassTheCert | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| PurpleSharp | :x: | :heavy_check_mark: | :heavy_check_mark: |
| Rubeus | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| RunasCs | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SafetyKatz | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SauronEye | :x: | :x: |  :heavy_check_mark:|
| Scout `⁷` | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SearchOutlook | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpSCOM `³` | :x: | :x: |  :heavy_check_mark: |
| Seatbelt | :heavy_check_mark: | :x: | :heavy_check_mark: |
| ShadowSpray `³` | :x: | :x: |  :heavy_check_mark:|
| Sharp-SMBExec | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpADWS | :x: | :x: |  :heavy_check_mark: |
| SharpAllowedToAct | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpAppLocker | :x: | :heavy_check_mark: | :heavy_check_mark: |
| SharpBlock `⁵` | :heavy_check_mark: | :heavy_check_mark: |  :x: |
| SharpBypassUAC | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpChisel | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpChrome | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpChromium | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpCloud | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpCOM | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpCookieMonster | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpCrashEventLog | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpDir | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpDoor `⁶` | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpDPAPI | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpDump | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| SharpEDRChecker | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| SharpExec | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| SharPersist | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| SharpFiles | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpFinder | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpGPOAbuse | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpHandler | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpHose | :x: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpHound | :x: | :x: |  :heavy_check_mark: |
| SharpKatz | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpKiller | :x: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpLaps | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpMapExec | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpMiniDump | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpMove | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpNamedPipePTH | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpNoPSExec | :x: | :x: |  :heavy_check_mark:|
| SharpPrinter | :x: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpRDP | :x: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpReg | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpSCCM | :x: | :x: |  :heavy_check_mark:|
| SharpSearch | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpSecDump | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpShares | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| SharpSMBSpray | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpSphere | :x: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpSpray | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpStay | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpSuccessor | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpSvc | :x: | :x: |  :heavy_check_mark: |
| SharpSystemTriggers `⁸` | :warning: | :warning: |  :warning:|
| SharpSniper | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpSQLPwn | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpTask | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| SharpTokenFinder | :x: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpUp | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| SharpView | :x: | :heavy_check_mark: |  :heavy_check_mark:|
| SharpWMI | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpWebServer | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpWifiGrabber | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpWSUS | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| SharpZeroLogon | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| Shhmon | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| Snaffler | :x: |:heavy_check_mark:|:x:|
| SpoolSample | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SqlClient | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| StandIn | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| StickyNotesExtract | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| SweetPotato | :x: | :heavy_check_mark: |  :heavy_check_mark:|
| ThreatCheck | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| ThunderFox |:heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark: |
| TruffleSnout | :x: | :heavy_check_mark: |  :heavy_check_mark:|
| TokenStomp | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| Watson | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |
| winPEAS | :x: | :heavy_check_mark: |  :heavy_check_mark: |
| WMIReg | :heavy_check_mark: | :heavy_check_mark: |  :heavy_check_mark:|
| Whisker | :x: | :x: |  :heavy_check_mark:|

### Note a piè di pagina

1. **ADCollector** — Ha come target specificamente .NET Framework **v4.6.1** (mappato alla colonna NET 4.7)
2. **AtYourService, Evasor** — Nessuna build AnyCPU, solo piattaforme x64/x86
3. **Certify, KrbRelay, KrbRelayUp, ShadowSpray** — Hanno come target specificamente .NET Framework **v4.7.2**
4. **CheeseTools** — La pipeline esiste ma non ha mai avuto una build completata con successo
5. **SharpBlock** — Compila solo NET 4.0 e NET 4.5; i passaggi per NET 4.7 sono disabilitati. Nessuna build AnyCPU (solo x64/x86)
6. **SharpDoor** — Pubblica solo binari x64 (compilati tramite script PowerShell)
7. **Scout** — Il repository originale è stato rimosso. I binari inclusi sono obsoleti e non più mantenuti
8. **SharpSystemTriggers** — La pipeline è **in pausa**. I binari esistenti potrebbero essere obsoleti

> **InveighZero** :warning: — La pipeline ha tutti i passaggi di build **disabilitati** ed è non funzionante. I binari esistenti nel repo provengono da build precedenti.

# Fonti / Crediti
I link per tutti questi fantastici strumenti sono qui sotto :)* [ADCollector](https://github.com/dev-2null/ADCollector) - Strumento C# per estrarre rapidamente informazioni preziose dall'ambiente Active Directory @dev-2null
* [ADCSPwn](https://github.com/bats3c/ADCSPwn) - Strumento C# per elevare i privilegi in una rete Active Directory forzando l'autenticazione dagli account macchina e inoltrandola al servizio certificati. @bats3c
* [ADSearch](https://github.com/tomcarver16/ADSearch) - Strumento C# per interrogare AD tramite il protocollo LDAP @tomcarver16 (Solo NET 4.7)
* [ADFSDump](https://github.com/fireeye/ADFSDump) - Uno strumento C# per estrarre ogni genere di dati utili da AD FS. @FireEye
* [AtYourService](https://github.com/mitchmoser/AtYourService) - Assembly .NET C# per l'enumerazione dei servizi @mitchmoser
* [BadAssMacros](https://github.com/Flangvik/BadAssMacros) - Generatore automatico di macro dannose basato su C# @Flangvik
* [BetterSafetyKatz](https://github.com/Flangvik/BetterSafetyKatz) - Fork di SafetyKatz che recupera dinamicamente l'ultima versione di Mimikatz, applica le firme di patching a runtime e carica Mimikatz in memoria tramite PE. @Flangvik
* [Certify](https://github.com/GhostPack/Certify) - Strumento C# per enumerare e sfruttare le configurazioni errate in Active Directory Certificate Services (AD CS). @harmj0y @tifkin_
* [CheeseTools](https://github.com/klezVirus/CheeseTools) - Strumenti sviluppati in proprio per il movimento laterale/l'esecuzione di codice @klezVirus
* [EDD]( https://github.com/FortyNorthSecurity/EDD) - Enumerate Domain Data è progettato per essere simile a PowerView ma in .NET @FortyNorthSecurity
* [Evasor](https://github.com/cyberark/Evasor) - Uno strumento da usare nella fase di post-exploitation per valutare e aggirare gli AV @CyberArk
* [Farmer](https://github.com/mdsecactivebreach/Farmer) - Raccoglie hash NetNTLM in un dominio Windows tramite un server WebDAV locale @domchell
* [ForgeCert](https://github.com/GhostPack/ForgeCert) - Usa un certificato CA rubato + chiave privata per forgiare certificati per utenti arbitrari. @tifkin_
* [GMSAPasswordReader](https://github.com/rvazarkar/GMSAPasswordReader) - Legge il blob della password da un account GMSA. @rvazarkar
* [DeployPrinterNightmare]( https://github.com/Flangvik/DeployPrinterNightmare) - Strumento C# per installare una stampante di rete condivisa sfruttando il bug PrinterNightmare per consentire ad altre macchine della rete una facile escalation dei privilegi @Flangvik
* [Grouper2](https://github.com/l0ss/Grouper2) - Strumento C# per individuare configurazioni errate legate alla sicurezza in Active Directory Group Policy. @mikeloss
* [Group3r](https://github.com/Group3r/Group3r) - Strumento C# per trovare vulnerabilità in AD Group Policy, ma fatto meglio di quanto facesse Grouper2. @mikeloss
* [Internal-Monologue](https://github.com/eladshamir/Internal-Monologue) - Recupera gli hash NTLM senza toccare LSASS @elad_shamir
* [KrbRelay](https://github.com/cube0x0/KrbRelay) - Framework C# per il relaying Kerberos @cube0x0
* [KrbRelayUp](https://github.com/Dec0ne/KrbRelayUp) - Escalation dei privilegi locale universale senza fix in ambienti di dominio Windows dove la firma LDAP non è applicata @dec0ne
* [LockLess](https://github.com/GhostPack/LockLess) - Consente la copia di file bloccati. @GhostPack
* [Moriarty](https://github.com/BC-SECURITY/Moriarty) - Enumera le KB mancanti, rileva varie vulnerabilità e suggerisce potenziali exploit per l'escalation dei privilegi in Windows
* [PassTheCert](https://github.com/AlmondOffSec/PassTheCert) - Strumento proof-of-concept per autenticarsi a un server LDAP/S con un certificato tramite Schannel. @AlmondOffSec
* [PurpleSharp](https://github.com/mvelazc0/PurpleSharp) - Strumento C# di simulazione degli avversari che esegue tecniche avversarie allo scopo di generare telemetria degli attacchi in ambienti Windows monitorati. @mvelazc0
* [Rubeus](https://github.com/GhostPack/Rubeus) - Toolkit C# per l'interazione diretta con Kerberos e i relativi abusi. @GhostPack
* [RunasCs](https://github.com/antonioCoco/RunasCs) - Versione open in C# del runas.exe integrato di Windows. @splinter_code
* [SafetyKatz](https://github.com/GhostPack/SafetyKatz) - Combinazione di una versione leggermente modificata del progetto Mimikatz di @gentilkiwi e del .NET PE Loader di @subTee. @GhostPack
* [SauronEye](https://github.com/vivami/SauronEye) - Strumento di ricerca C# per trovare file specifici contenenti parole chiave specifiche (.doc, .docx, .xls, .xlsx). @_vivami
* [Scout](https://github.com/jaredhaight/scout) - Un assembly .NET per eseguire ricognizione contro gli host di una rete. @jaredhaight (**Repo rimosso — i binari sono obsoleti**)
* [SearchOutlook](https://github.com/RedLectroid/SearchOutlook) - Strumento C# per cercare parole chiave in un'istanza in esecuzione di Outlook @RedLectroid
* [Seatbelt](https://github.com/GhostPack/Seatbelt) - Esegue una serie di "safety checks" di ricognizione dell'host orientati alla sicurezza. @GhostPack
* [ShadowSpray](https://github.com/Dec0ne/ShadowSpray) - Uno strumento per distribuire Shadow Credentials sull'intero dominio nella speranza di abusare di DACL GenericWrite/GenericAll a lungo dimenticate su altri oggetti del dominio.
* [Sharp-SMBExec](https://github.com/checkymander/Sharp-SMBExec) - Una conversione nativa in C# dello script PowerShell Invoke-SMBExec di Kevin Robertson @checkymander
* [SharpADWS](https://github.com/wh0amitz/SharpADWS) - Ricognizione e sfruttamento di Active Directory per Red Team tramite Active Directory Web Services (ADWS). @wh0amitz
* [SharpAllowedToAct](https://github.com/pkb1s/SharpAllowedToAct) - Implementazione C# del takeover di un oggetto computer tramite delega vincolata basata sulle risorse (msDS-AllowedToActOnBehalfOfOtherIdentity) @pkb1s
* [SharpAppLocker](https://github.com/Flangvik/SharpAppLocker) - Porting C# del cmdlet PS Get-AppLockerPolicy con funzionalità estese @Flangvik
* [SharpBlock](https://github.com/CCob/SharpBlock) - Un metodo per bypassare le DLL di proiezione attiva degli EDR impedendo l'esecuzione del punto di ingresso. @CCob
* [SharpBypassUAC](https://github.com/FatRodzianko/SharpBypassUAC) - Strumento C# per bypass UAC @rodzianko
* [SharpChisel](https://github.com/shantanu561993/SharpChisel) - Wrapper C# per Chisel. @shantanu561993
* [SharpChrome](https://github.com/GhostPack/SharpDPAPI) - Implementazione specifica per Chrome di SharpDPAPI in grado di decrittare/analizzare cookie e credenziali di accesso. @GhostPack
* [SharpChromium](https://github.com/djhohnstein/SharpChromium) - Progetto C# per recuperare dati Chromium, come cookie, cronologia e credenziali salvate. @djhohnstein
* [SharpCloud](https://github.com/chrismaddalena/SharpCloud) - Semplice strumento C# per verificare l'esistenza di file di credenziali relativi ad AWS, Microsoft Azure e Google Compute. @chrismaddalena
* [SharpCOM](https://github.com/rvrsh3ll/SharpCOM) - Porting C# di Invoke-DCOM @424f424f
* [SharpCookieMonster](https://github.com/m0rv4i/SharpCookieMonster) - Strumento C# per estrarre i cookie del browser @m0rv4i
* [SharpCrashEventLog](https://github.com/slyd0g/SharpCrashEventLog) - Porting C# di LogServiceCrash @slyd0g @limbenjamin
* [SharpDir](https://github.com/jnqpblc/SharpDir) - Strumento C# per cercare file sia in file system locali che remoti. @jnqpblc
* [SharpDoor](https://github.com/infosecn1nja/SharpDoor) - Strumento C# per consentire più sessioni RDP (Remote Desktop) applicando una patch al file termsrv.dll. @infosecn1nja
* [SharpDPAPI](https://github.com/GhostPack/SharpDPAPI) - Porting C# di alcune funzionalità DPAPI di Mimikatz. @GhostPack
* [SharpDump](https://github.com/GhostPack/SharpDump) - SharpDump è un porting C# della funzionalità Out-Minidump.ps1 di PowerSploit. @GhostPack
* [SharpEDRChecker](https://github.com/PwnDexter/SharpEDRChecker) - Strumento C# per verificare la presenza di prodotti difensivi noti come antivirus, EDR e strumenti di logging @PwnDexter
* [SharPersist](https://github.com/fireeye/SharPersist) - Toolkit C# per la persistenza.
* [SharpExec](https://github.com/anthemtotheego/SharpExec) - SharpExec è uno strumento C# di sicurezza offensiva progettato per facilitare il movimento laterale. @anthemtotheego
* [SharpFiles](https://github.com/fullmetalcache/SharpFiles) - Strumento C# per cercare file in base all'output di SharpShares. @fullmetalcache
* [SharpFinder](https://github.com/s0lst1c3/SharpFinder) - Cerca file che corrispondono a criteri specifici nelle condivisioni leggibili all'interno del dominio
* [SharpGPOAbuse](https://github.com/FSecureLABS/SharpGPOAbuse) - SharpGPOAbuse è un'applicazione .NET scritta in C# che può essere usata per sfruttare i diritti di modifica di un utente su un oggetto Criteri di gruppo (GPO). @FSecureLABS
* [SharpHandler](https://github.com/jfmaes/SharpHandler) - Strumento C# per rubare/duplicare handle di LSASS @Jean_Maes_1994
* [SharpHose](https://github.com/ustayready/SharpHose) - Strumento asincrono di password spraying in C# per ambienti Windows. @ustayready
* [SharpHound](https://github.com/BloodHoundAD/SharpHound) - Versione C# 2022 dell'Ingestor di BloodHound 4.x. @BloodHoundAD
* [SharpKatz](https://github.com/b4rtik/SharpKatz) - Porting C# PURO di funzionalità significative di MimiKatz come logonpasswords, dcsync, ecc. @b4rtik
* [SharpKiller](https://github.com/S1lkys/SharpKiller) - Bypass AMSI permanente di @ZeroMemoryEx portato a .NET Framework 4.8 @S1lky_1337
* [SharpLaps](https://github.com/swisskyrepo/SharpLAPS) - Uno strumento C# per recuperare le password LAPS da LDAP @pentest_swissky
* [SharpMapExec](https://github.com/cube0x0/SharpMapExec) - Versione C# dello strumento CrackMapExec di @byt3bl33d3r @cube0x0
* [SharpMiniDump](https://github.com/b4rtik/SharpMiniDump) - Strumento C# per creare un minidump del processo LSASS dalla memoria @b4rtik
* [SharpNamedPipePTH](https://github.com/S3cur3Th1sSh1t/SharpNamedPipePTH) - Strumento C# per Pass-the-Hash su Named Pipes. @S3cur3Th1sSh1t
* [SharpNoPSExec](https://github.com/juliourena/SharpNoPSExec) - Strumento C# che consente l'esecuzione di comandi senza file per il movimento laterale. @juliourena
* [SharpMove](https://github.com/0xthirteen/SharpMove) - Strumento C# per eseguire tecniche di movimento laterale @0xthirteen
* [SharpPrinter](https://github.com/rvrsh3ll/SharpPrinter) - Strumento C# per scoprire stampanti su una rete @424f424f
* [SharpRDP](https://github.com/0xthirteen/SharpRDP) - Applicazione console C# basata sul protocollo Remote Desktop Protocol per l'esecuzione autenticata di comandi @0xthirteen
* [SharpReg](https://github.com/jnqpblc/SharpReg) - Strumento C# per interagire con l'API del servizio Remote Registry. @jnqpblc
* [SharpSecDump](https://github.com/G0ldenGunSec/SharpSecDump) - Porting C# della funzionalità di dump remoto di SAM + LSA Secrets di secretsdump.py di impacket @G0ldenGunSec
* [SharpSCCM](https://github.com/Mayyhem/SharpSCCM) - Utilità C# per interagire con SCCM @_Mayyhem
* [SharpSCOM](https://github.com/breakfix/SharpSCOM) - Strumento C# per lo sfruttamento di SCOM, inclusi takeover dell'agente e movimento laterale. @breakfix
* [SharpSearch](https://github.com/djhohnstein/SharpSearch) - Strumento C# per cercare file che corrispondono a un pattern. @djhohnstein
* [SharpSMBSpray](https://github.com/rvrsh3ll/SharpSMBSpray) - Strumento C# per il password spraying SMB. @424f424f
* [SharpShares](https://github.com/djhohnstein/SharpShares) - Enumera tutte le condivisioni di rete nel dominio corrente. @djhohnstein
* [SharpSphere](https://github.com/JamesCooteUK/SharpSphere) - SharpSphere C# ha la capacità di interagire con i sistemi operativi guest delle macchine virtuali gestite da vCenter. @jkcoote & @grzryc
* [SharpSpray](https://github.com/jnqpblc/SharpSpray) - Strumento C# per eseguire un attacco di password spraying contro tutti gli utenti di un dominio tramite LDAP. @jnqpblc
* [SharpStay](https://github.com/0xthirteen/SharpStay) - Progetto .NET per installare la persistenza. @0xthirteen
* [SharpSuccessor](https://github.com/yourusername/SharpSuccessor) - Strumento C# per sfruttare la vulnerabilità di escalation dei privilegi BadSuccessor / dMSA
* [SharpSvc](https://github.com/jnqpblc/SharpSvc) - Strumento C# per interagire con l'API SC Manager. @jnqpblc (Solo NET 4.7)
* [SharpSystemTriggers](https://github.com/cube0x0/SharpSystemTriggers) - Raccolta C# di trigger di autenticazione remota per forzare le macchine Windows. @cube0x0
* [SharpSniper](https://github.com/HunnicCyber/SharpSniper) - SharpSniper è un semplice strumento per trovare l'indirizzo IP di questi utenti così da poter prendere di mira la loro macchina. @hunniccyber
* [SharpSQLPwn](https://github.com/lefayjey/SharpSQLPwn) - Strumento C# per identificare e sfruttare le debolezze nelle istanze MSSQL in ambienti Active Directory. @lefayjey
* [SharpTask](https://github.com/jnqpblc/SharpTask) - Strumento C# per interagire con l'API del servizio Utilità di pianificazione (Task Scheduler). @jnqpblc
* [SharpTokenFinder](https://github.com/HuskyHacks/SharpTokenFinder) - Implementazione C# di TokenFinder. Ruba i token di accesso M365 dalle app desktop di Office
* [SharpUp](https://github.com/GhostPack/SharpUp) - Porting C# di varie funzionalità di PowerUp. @GhostPack
* [SharpView](https://github.com/tevora-threat/SharpView) - Implementazione C# di PowerView di harmj0y. @tevora-threat
* [SharpWMI](https://github.com/GhostPack/SharpWMI) - Implementazione C# di varie funzionalità WMI. @GhostPack
* [SharpWebServer](https://github.com/mgeeky/SharpWebServer) - Un semplice server HTTP & WebDAV orientato al Red Team scritto in C# con funzionalità di cattura degli hash Net-NTLM. @mariuszbit
* [SharpWifiGrabber](https://github.com/r3nhat/SharpWifiGrabber) - Sharp Wifi Password Grabber recupera in chiaro le password Wi-Fi da tutti i profili WLAN salvati su una workstation. @r3n_hat
* [SharpWSUS](https://github.com/nettitude/SharpWSUS) - Strumento C# per il movimento laterale tramite WSUS. @naborstudio
* [SharpZeroLogon](https://github.com/nccgroup/nccfsas/tree/main/Tools/SharpZeroLogon) - Porting C# di CVE-2020-1472 , noto anche come Zerologon. @buffaloverflow
* [Shhmon](https://github.com/matterpreter/Shhmon) - Neutralizzazione di Sysmon tramite scaricamento del driver. @Shhmon
* [SpoolSample](https://github.com/leechristensen/SpoolSample) - Strumento C# per forzare gli host Windows ad autenticarsi verso altre macchine tramite l'interfaccia RPC MS-RPRN. @tifkin_
* [Snaffler](https://github.com/SnaffCon/Snaffler) - Strumento C# per pentester che aiuta a trovare caramelle deliziose. @l0ss and @Sh3r4
* [SqlClient](https://github.com/FortyNorthSecurity/SqlClient) - Client mssql C# .NET per accedere ai dati del database tramite beacon. @FortyNorthSecurity
* [StandIn](https://github.com/FuzzySecurity/StandIn) - Piccolo toolkit post-compromissione AD basato su C#. @FuzzySec
* [StickyNotesExtract](https://github.com/V1V1/SharpScribbles) - Strumento C# che estrae dati dal database delle Note rapide (Sticky Notes) di Windows. @V1V1
* [SweetPotato](https://github.com/CCob/SweetPotato) - Escalation dei privilegi da Local Service a SYSTEM da Windows 7 a Windows 10 / Server 2019. @CCob
* [ThreatCheck](https://github.com/rasta-mouse/ThreatCheck) - Strumento C# per identificare i byte che Microsoft Defender / AMSI contrassegna come dannosi. @rasta-mouse
* [ThunderFox](https://github.com/V1V1/SharpScribbles) - C# Recupera dati (contatti, email, cronologia, cookie e credenziali) da Thunderbird e Firefox. @V1V1
* [TruffleSnout](https://github.com/dsnezhkov/TruffleSnout) - Toolkit iterativo di discovery AD basato su C# per operatori offensivi. @dsnezhkov
* [TokenStomp](https://github.com/MartinIngesen/TokenStomp) - Implementazione C# del difetto di rimozione dei privilegi dei token scoperto da @GabrielLandau / Elastic. @Mrtn9
* [Watson](https://github.com/rasta-mouse/Watson) - Enumera le KB mancanti e suggerisce exploit per utili vulnerabilità di escalation dei privilegi. @rasta-mouse
* [winPEAS](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite) - PEASS - Privilege Escalation Awesome Scripts (winPEAS). @carlospolop
* [WMIReg](https://github.com/airzero24/WMIReg) - PoC C# per interagire con hive del registro locali/remoti tramite WMI. @airzero24
* [Whisker](https://github.com/eladshamir/Whisker) - Whisker è uno strumento C# per impadronirsi degli account utente e computer di Active Directory manipolando il loro attributo msDS-KeyCredentialLink. @elad_shamir
Scarica lo strumento