Jump to content
Kev

SharpShot -

Recommended Posts

Posted

Trivial .NET desktop capturing for Red Team operations

Uses only legit stuff (in order to bypass Endpoint Protection).

 

Components:

  • minimal .NET screen capture binary,
  • script to deploy, run, fetch the screenshot and cleanup.

 

Target user must have an active session on the target host (query user may be used).

 

capture binary

The SharpShot.sln is a super minimal .NET screen capturing project in C#.

 

Takes the destination .png file (with full pathname) as a mandatory argument.

 

Build tested using Visual Studio 2019 (Community Edition), targets .NET Framework version 4.5.

 

Post-build hook converts the console exe to GUI type in order to run silently (without popping up a console window).

 

deploy script

The script screenshot.sh is just an example how I used it in an engagement. Should be customized before use.

 

Depends on impacket (wmiexec) and samba (smbclient).

 

Uses the legit Windows Task Scheduler to run the capture binary as the target user. Probably little bit noisy, but bypasses AVs.

 

Download SharpShot-master.zip

or

git clone https://github.com/tothi/SharpShot.git

 

Source

Posted

Asta e tot:

 

Rectangle bounds = Screen.GetBounds(Point.Empty);
using (Bitmap bitmap = new Bitmap(bounds.Width, bounds.Height))
{
using (Graphics g = Graphics.FromImage(bitmap))
{
g.CopyFromScreen(Point.Empty, Point.Empty, bounds.Size);
}
bitmap.Save(fullpath, format);

}

  • Upvote 2
Posted

Da, tot ce face util e ce a postat gigiRoman. In rest e o porcarie. Foloseste wmiexec si smbclient sa trimita screenshot? 

Mai bine luati acea bucata de cod si o folositi in orice alt mod. 

  • Upvote 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...