MSBuildAPICaller is a part of the Sharp-Suite, a collection of tools used for offensive operations, allowing users to interact with the MSBuild API, enabling various malicious activities. The tool provides a way to execute arbitrary MSBuild scripts, which can be used to bypass security controls and evade detection. This can be particularly useful in red teaming and penetration testing scenarios. MSBuildAPICaller is a powerful tool in the hands of a skilled operator, allowing for creative and targeted attacks.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Emulates Docker HTTP API with event logging and AWS deployment script.
DET (extensible) Data Exfiltration Toolkit is a proof of concept tool for performing Data Exfiltration using multiple channels simultaneously.
Learn how to create new Malleable C2 profiles for Cobalt Strike to avoid detection and signatured toolset
A tool for security researchers and penetration testers to automate the process of finding sensitive information on a target domain.
Utilizing Alternate Data Streams (ADS) to bypass AppLocker default policies by loading DLL/CPL binaries.
PwnAuth is an open-source tool for generating and managing authentication tokens for penetration testing and red teaming exercises.
A full-featured reconnaissance framework for web-based reconnaissance with a modular design.
C3 is a framework for creating custom C2 channels, integrating with existing offensive toolkits.
Collection of Return-Oriented Programming challenges for practicing exploitation skills.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.