SharpCollection: Nightly Compiled C# Offensive Tool Builds via Azure DevOps
Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
At a glance
- What is it?
- SharpCollection is a GitHub repository that delivers nightly-compiled binaries of common C# offensive security tools, built automatically from their upstream master branches across .NET Framework 4.0, 4.5, and 4.7 targets. It is intended for penetration testers and red teamers who work in lab environments, CTF challenges, and detection mapping, not for direct deployment in client engagements.
- Who is it for?
- SharpCollection is useful for penetration testers and red teamers who need precompiled C# offensive tools quickly for lab work, CTF challenges, HackTheBox, or detection engineering. Before using any binary from this repository in a real engagement, review the binary with a decompiler such as dnSpy as the README recommends; the repo makes no guarantee that the compiled code matches what a client environment expects or trusts.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- GitHub does not report a main language for this repository.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What SharpCollection Solves for Red Teamers
Many C# offensive tools are distributed as source code only. Compiling them yourself requires a Windows build environment with the right .NET SDK version, and the tool's master branch may have dependencies that make fresh builds fail at inconvenient times. SharpCollection eliminates that step by running a nightly Azure DevOps pipeline that compiles each tool from its upstream master branch and pushes the resulting binaries to this repository.
The repository structure is organized by .NET Framework version and architecture. The top-level directories are `NetFramework_4.0_Any/`, `NetFramework_4.0_x64/`, `NetFramework_4.0_x86/`, `NetFramework_4.5_Any/`, `NetFramework_4.5_x64/`, `NetFramework_4.5_x86/`, `NetFramework_4.7_Any/`, `NetFramework_4.7_x64/`, and `NetFramework_4.7_x86/`. A red teamer who knows which .NET version and architecture their target environment uses can navigate directly to the right folder and copy the binary, bypassing the build step entirely.
The README includes one important note for users of Cobalt Strike's execute-assembly: only binaries compiled with the "Any CPU" configuration are accepted by that feature. The `NetFramework_*_Any/` directories are the relevant ones for that workflow.
The Azure DevOps Pipeline and Nightly Build Cadence
The build automation runs each night at 03:00 AM. The Azure DevOps pipeline checks for new commits to the master branch of each included tool. If the upstream repository has new commits, the pipeline fetches the updated source, compiles it for each supported framework target and architecture combination, and pushes the fresh binaries to SharpCollection.
The pipeline is publicly visible at dev.azure.com/FlangvikDev/SharpRelease, which means anyone can inspect which tools were built on a given night and whether a build step failed. The README uses three status symbols in its availability table: a checkmark for actively built, an X for not built, and a warning symbol for tools where the pipeline exists but all build steps are disabled. The warning status currently applies to InveighZero across all three .NET Framework versions. Some tools are not available for all framework versions because their source code targets a specific .NET version; Certify, KrbRelay, KrbRelayUp, and ShadowSpray are documented as targeting v4.7.2 only, while ADCollector targets v4.6.1.
The Full Tool List and How to Navigate It
The README table lists over 80 tools. A representative selection includes ADCollector, BetterSafetyKatz, Certify, Grouper2, KrbRelay, KrbRelayUp, Rubeus, RunasCs, SafetyKatz, Seatbelt, SharpDPAPI, SharpHound, SharpRDP, SharpSCCM, and WinPwn. Each row shows which .NET framework versions have available builds.
To use the collection, a tester clones the repository or browses the GitHub interface to the directory matching their target .NET version and CPU architecture, then downloads the binary for the tool they need. There are no install scripts and no package manager; the workflow is browse, copy, and run. The README does not document individual tool usage; each tool's own repository is the source of documentation for flags and behavior. The README author (@Flangvik on X) accepts requests for adding missing tools via GitHub issues or direct message.
OpSec Warning: Never Deploy Blindly
The README contains an explicit warning that the text reproduced here preserves in full: "Should I blindly deploy any of these binaries during real-life engagements? F*ck no, always look through anything that you deploy on a client machine or network."
The README recommends using a tool like dnSpy or dnSpyEx to inspect any binary before deployment. The stated safe uses are lab environments, virtual machines, HackTheBox, and detection mapping. This warning exists because the binaries are compiled from upstream master branches, not from pinned, reviewed commits. A tool's master branch may include features or changes that are inappropriate for a specific engagement, or the binary content may differ from what a client's security controls expect. Detection engineers will find the nightly build cadence useful precisely because it tracks master; operators who need stability and auditability need a different source.
How SharpCollection Differs from Ghostpack
Ghostpack is a collection of C# offensive tools maintained by SpectreOps, the security company behind BloodHound. It includes tools like Rubeus, Seatbelt, SharpDPAPI, and SharpDump, and each tool in the collection is maintained and versioned by SpectreOps directly. SharpCollection builds several Ghostpack tools from their upstream sources as part of its wider compilation sweep.
The key difference is curation. Ghostpack is a curated set of tools with explicit version control and direct maintainer involvement. SharpCollection is a compilation service that tracks many repositories, including Ghostpack tools and dozens of others maintained by different authors, and provides fresh binaries every night. A team that needs a specific, audited version of Rubeus should go to the Ghostpack repository. A team that wants the latest master build of every tool in one place uses SharpCollection, with the understanding that the binaries should be reviewed before use.
Maintenance and License Considerations
The last push to SharpCollection was on 2026-09-27. The repository is not archived and shows continuous nightly activity because the pipeline runs whether or not the README itself is updated. This makes the commit history less useful for tracking changes to the repository's own content versus new binary outputs from the pipeline.
The repository does not state an explicit license for the collection itself. Individual tools in the collection carry their own licenses, which vary by project. Rubeus, Seatbelt, and SharpDPAPI are under open-source licenses maintained by their authors; others may have different terms. A team using SharpCollection in a commercial engagement should verify the license terms of each specific tool they deploy. The README's OpSec guidance applies to all uses, regardless of licensing.
Editorial conclusion
SharpCollection is useful for penetration testers and red teamers who need precompiled C# offensive tools quickly for lab work, CTF challenges, HackTheBox, or detection engineering. Before using any binary from this repository in a real engagement, review the binary with a decompiler such as dnSpy as the README recommends; the repo makes no guarantee that the compiled code matches what a client environment expects or trusts. The repository has no stated license, and the individual tools have their own licenses. The last push was on 2026-09-27.
Frequently asked questions
What .NET Framework versions does SharpCollection support?
SharpCollection builds tools for .NET Framework 4.0, 4.5, and 4.7, with separate binaries for x64, x86, and Any CPU architectures. Not every tool is available for all three versions; the availability table in the README shows which combinations are built for each tool.
Why are some tools only available for .NET 4.7 and not older versions?
Some tools require APIs or features introduced in later .NET Framework versions. The README notes that Certify, KrbRelay, KrbRelayUp, and ShadowSpray target .NET v4.7.2 specifically, while ADCollector targets v4.6.1, which is why those tools are not compiled for older framework targets.
Is it safe to use SharpCollection binaries in a live client engagement?
The README explicitly says no. It states that binaries should never be deployed blindly during real-life engagements and recommends using a decompiler such as dnSpy to inspect any binary before putting it on a client machine or network. The collection is described as suitable for lab environments, virtual machines, HackTheBox, and detection mapping.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/flangvik-sharpcollection)