SharpC2 is a Command and Control (C2) Framework developed in C# that enables remote access and control of compromised systems during security assessments and penetration testing activities. The framework features a modular architecture that allows for customization and extension of its capabilities. It supports multiple communication protocols to establish and maintain connections with target systems. The tool includes a user interface designed to facilitate management of compromised endpoints and execution of commands across controlled systems. Its open-source design allows security professionals to examine, modify, and adapt the codebase to meet specific testing requirements. SharpC2 provides documentation to assist users in deployment and configuration. The framework is primarily intended for authorized security testing scenarios where organizations need to assess their defensive capabilities against command and control attacks.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
PyBOF is a Python library that enables in-memory loading and execution of Beacon Object Files (BOFs) with support for argument passing and function targeting.
An Azure Function that validates and relays Cobalt Strike beacon traffic based on Malleable C2 profile authentication.
A command that builds and executes command lines from standard input, allowing for the execution of commands with multiple arguments.
A suite of tools for Wi-Fi network security assessment and penetration testing.
SharpEDRChecker scans system components to detect security products and tools.
Tool for enumerating proxy configurations and generating CobaltStrike-compatible shellcode.
Advanced command and control tool for red teaming and adversary simulation with extensive features and evasion capabilities.
SharpShares efficiently enumerates and maps network shares and resolves names within a domain.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.