SharpC2 is a Command and Control Framework written in C# that provides a robust and flexible solution for remote access and control of compromised systems. It offers a range of features, including modular design, multi-protocol support, and a user-friendly interface, making it a powerful tool for penetration testers and red teams. With its extensive documentation and open-source nature, SharpC2 is an ideal choice for those looking to develop and customize their own command and control solutions.
FEATURES
SIMILAR TOOLS
A modular, menu-driven tool for building repeatable, time-delayed, distributed security events.
Collection of Windows oneliners for executing arbitrary code and downloading remote payloads.
Comprehensive tutorial on modern exploitation techniques with a focus on understanding exploitation from scratch.
A visual guide illustrating attack paths and techniques for exploiting vulnerabilities in GitHub Actions configurations.
A standalone man-in-the-middle attack framework used for phishing login credentials and bypassing 2-factor authentication.
An Android port of the Radamsa fuzzing tool compiled with Android NDK to support Android ABIs for security testing on mobile platforms.
Create a vulnerable active directory for testing various Active Directory attacks.
MITRE Caldera™ is a cybersecurity platform that automates adversary emulation and supports red team operations through a modular framework built on MITRE ATT&CK.
A Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.