SharpSploit is an open-source .NET post-exploitation library written in C# for offensive security and red-team operations on Windows. It is designed to expose and simplify the use of the .NET attack surface and provides reusable functionality for in-memory execution, process interaction, credential access–adjacent tradecraft, and other post-compromise operations. The project is conceptually related to PowerSploit and incorporates ideas and code influenced by projects and research such as PowerView, Tokenvator, Mimikatz, AMSI bypass research, PowerShell logging bypass research, token-duplication UAC bypass work, and dynamic invocation techniques.
SharpSploit is not a standalone malware family in the conventional sense but a dual-use offensive library that has been incorporated into adversary tooling and public command-and-control frameworks. It is used extensively by Covenant and its code patterns have appeared in malware and intrusion operations. Reported abuse includes use of SharpSploit-derived dynamic API resolution and in-memory patching logic in VenomRAT, as well as use of SharpSploit code for reflective .NET injection during Operation Cache Panda to execute malicious assemblies without writing modules to disk. These uses support defense evasion and post-exploitation by enabling fileless execution and reducing static detection opportunities.
The library is associated with Windows and the .NET ecosystem and is primarily relevant after initial compromise, where operators use it to execute payloads in memory, inject or load .NET components reflectively, and facilitate broader offensive actions. Because SharpSploit is a reusable framework component rather than a single-purpose payload, its exact behavior depends on the tool or actor embedding it.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive security project referenced as inspiration for VenomRAT's AMSI/ETW bypass and D/Invoke-style functionality; not described here as malware itself.
Code from SharpSploit was used to inject malicious .NET payloads in memory for stealthier execution.
Offensive .NET library used by Covenant for functionality; mentioned as a supporting component rather than the main subject.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.