# mvelazc0/defcon27_csharp_workshop

Writing custom backdoor payloads with C# - Defcon 27 Workshop

Repository: https://github.com/mvelazc0/defcon27_csharp_workshop
Canonical: https://ross.abutalabs.com/products/defcon27_csharp_workshop
Language: C#
License Family: other
Topics: csharp, payloads, redteam
Last push: 2022-03-18T02:59:51+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2577, "days_push": 1629, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1190, forks 271 (observed 2026-08-28T04:03:55.888030+00:00)

## What it is
A Defcon 27 workshop repository with 8 hands-on labs teaching how to write custom backdoor payloads in C# targeting C2 frameworks like Metasploit, Empire, and Cobalt Strike. It covers techniques such as shellcode injection, process hollowing, DLL injection, and antivirus bypass from both attack and defense perspectives.

## Use cases
- learn to write custom C2 payloads in C#
- understand shellcode injection techniques
- study process hollowing and DLL injection
- learn antivirus evasion techniques
- red team training on payload development
- understand offensive techniques from a defense perspective

## When to choose
- you want hands-on labs for offensive .NET/C# development
- you're preparing for red team work or security certifications
- you want to understand Windows injection and evasion techniques

## When to avoid
- you need production-ready offensive tooling rather than educational labs
- you're looking for defensive-only tooling
- you have no interest in Windows/.NET environments

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: security, penetration-testing, reverse-engineering
- domain: security, penetration-testing, tutorials, windows
- platform: windows, cross-platform, dotnet
- tags: red-team, offensive-security, csharp, defcon, workshop, malware-development, shellcode-injection, process-injection, antivirus-evasion

## Member repositories
- mvelazc0/defcon27_csharp_workshop (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:55.888030+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:23:05.117581+00:00, confidence not recorded.
  - readme: https://github.com/mvelazc0/defcon27_csharp_workshop (fetched 2026-08-28T04:03:55.888030+00:00, sha e8d1438fb847)
- Data as of 2026-08-30T08:39:29.467469+00:00.
