logo

SharpParty: Process Injection in C#

ID: 7db225e0-b47c-5a1c-b1ce-58e23c25c6cc

STIX ID: report--7db225e0-b47c-5a1c-b1ce-58e23c25c6cc

Feed Name: LevelBlue SpiderLabs Blog

Date Published: 2025-11-11

Date Updated: 2026-04-28

Author: Will Rabb

...
...

The report presents Stroz Friedberg’s SharpParty, a C# port of SafeBreach Labs’ PoolParty process-injection techniques that abuse Windows Thread Pools, designed to broaden red team options and support MSBuild-based and in-memory execution. It explains the rationale for a C# implementation, shares testing results showing mixed EDR outcomes (including an initial Microsoft Defender for Endpoint bypass later addressed), and recounts a client engagement where execution succeeded and detections were delayed, underscoring both potential improvements and detection gaps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.