Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
WFH — Frida-basiertes dynamisches Analysewerkzeug, das automatisch DLL-Sideloading- und COM-Hijacking-Schwachstellen in Windows-Ausführbaren Dateien durch Laufzeitinstrumentierung und IAT-Analyse identifiziert. | Kitploit
Tools/GitHubGitHub/conscioushacker/wfh
Dynamische Analyse (Sandboxing)ExploitationFuzzingBinäranalyse
GitHubconscioushacker/wfh

WFH

Frida-basiertes dynamisches Analysewerkzeug, das automatisch DLL-Sideloading- und COM-Hijacking-Schwachstellen in Windows-Ausführbaren Dateien durch Laufzeitinstrumentierung und IAT-Analyse identifiziert.

Repository anzeigen
43672vor 4 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

Windows Feature Hunter (WFH)

Windows Feature Hunter (WFH) ist ein Proof-of-Concept-Python-Skript, das Frida, ein dynamisches Instrumentierungs-Toolkit, verwendet, um bei der potenziellen Identifizierung von allgemeinen „Schwachstellen“ oder „Features“ in Windows-Ausführbaren zu helfen. WFH hat derzeit die Fähigkeit, potenzielle Dynamic Linked Library (DLL)-Sideloading- und Component Object Model (COM)-Hijacking-Möglichkeiten im großen Maßstab automatisch zu identifizieren.

DLL-Sideloading nutzt die Windows Side-by-Side (WinSXS)-Assembly, um eine bösartige DLL aus der Side-by-Side (SXS)-Auflistung zu laden. COM-Hijacking ermöglicht es einem Angreifer, bösartigen Code einzuschleusen, der anstelle legitimer Software ausgeführt werden kann, indem die COM-Referenzen und -Beziehungen gekapert werden. WFH gibt die potenziellen Schwachstellen aus und schreibt eine CSV-Datei, die die potenziellen Schwachstellen in den Ziel-Windows-Ausführbaren enthält.

Table of Contents

  • Windows Feature Hunter (WFH)
    • WFH Install
    • WFH Help
    • WFH Usage
      • WFH DLL Sideloading Identification
      • WFH COM Hijacking Identification
    • WFH Use Cases
      • Native Windows Signed Binaries
  • Windows Feature Hunter Dridex (WFH Dridex)
    • WFH Dridex Install
    • WFH Dridex Dependencies
    • WFH Dridex Usage
      • WFH Dridex DLL Sideloading Identification
    • WFH Dridex DLL Sideloads from System32
      • WFH vs WFH Dridex Results
  • HijackLibs Contribution

WFH Install

root@kitploit:~
pip install -r requirements.txt

WFH Help

root@kitploit:~
PS C:\Tools\WFH > python .\wfh.py -h
usage: wfh.py [-h] -t T [T ...] -m {dll,com} [-v] [-timeout TIMEOUT]

Windows Feature Hunter

optional arguments:
  -h, --help            show this help message and exit
  -t T [T ...], -targets T [T ...]
                        list of target windows executables
  -m {dll,com}, -mode {dll,com}
                        vulnerabilities to potentially identify
  -v, -verbose          verbose output from Frida instrumentation
  -timeout TIMEOUT      timeout value for Frida instrumentation

EXAMPLE USAGE
    NOTE: It is recommended to copy target binaries to the same directory as wfh for identifying DLL Sideloading

    DLL Sideloading Identification (Single):        python wfh.py -t .\mspaint.exe -m dll
    DLL Sideloading Identification (Verbose):       python wfh.py -t .\mspaint.exe -m dll -v
    DLL Sideloading Identification (Timeout 30s):   python wfh.py -t .\mspaint.exe -m dll -timeout 30
    DLL Sideloading Identification (Wildcard):      python wfh.py -t * -m dll
    DLL Sideloading Identification (List):          python wfh.py -t .\mspaint.exe .\charmap.exe -m dll

    COM Hijacking Identification (Single):          python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com
    COM Hijacking Identification (Verbose):         python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com -v
    COM Hijacking Identification (Timeout 60s):     python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com -timeout 60
    COM Hijacking Identification (Wildcard):        python wfh.py -t * -m com -v
    COM Hijacking Identification (List):            python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" "C:\Windows\System32\notepad.exe" -m com -v

WFH Usage

WFH DLL Sideloading Identification

Zuerst müssen Sie die ausführbaren Dateien, die Sie analysieren möchten, in dasselbe Verzeichnis wie WFH kopieren.

root@kitploit:~
PS C:\Tools\WFH > copy C:\Windows\System32\mspaint.exe .
PS C:\Tools\WFH > copy C:\Windows\System32\charmap.exe .
PS C:\Tools\WFH > dir


    Directory: C:\Tools\WFH


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         5/14/2021   2:12 PM                .vscode
-a----          5/6/2021   2:39 PM           1928 .gitignore
-a----         12/7/2019   2:09 AM         198656 charmap.exe
-a----         5/18/2021   7:39 AM           6603 loadlibrary.js
-a----          4/7/2021  12:48 PM         988160 mspaint.exe
-a----         5/18/2021   7:53 AM           8705 README.md
-a----         5/17/2021  11:27 AM           5948 registry.js
-a----          5/6/2021   2:41 PM             11 requirements.txt
-a----         5/18/2021   8:35 AM          10623 wfh.py

Jetzt können Sie wfh gegen die ausführbaren Dateien ausführen, um DLL-Sideloading-Möglichkeiten zu identifizieren.

root@kitploit:~
PS C:\Tools\WFH > python .\wfh.py -t * -m dll
==================================================
Running Frida against charmap.exe
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to charmap.exe-raw.log
[*] Writing Potential DLL Sideloading to charmap.exe-sideload.log
--------------------------------------------------
==================================================
Running Frida against mspaint.exe
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
        [-] Potential DllExport Sideloading: GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to mspaint.exe-raw.log
[*] Writing Potential DLL Sideloading to mspaint.exe-sideload.log
--------------------------------------------------
==================================================
[*] Writing dll results to dll_results.csv

PS C:\Tools\WFH > type .\dll_results.csv
Executable,WinAPI,DLL,EntryPoint / WinAPI Args
charmap.exe,LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
charmap.exe,LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE
mspaint.exe,LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
mspaint.exe,GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
mspaint.exe,LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
mspaint.exe,LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

Wenn Sie eine ausführlichere Ausgabe bevorzugen, können Sie "-v" verwenden, um jede Nachricht von Frida zu sehen, das die Windows-API-Aufrufe instrumentiert. Sie können diese Ausgabe auch in der Rohprotokolldatei anzeigen.

root@kitploit:~
PS C:\Tools\WFH > python .\wfh.py -t * -m dll -v
==================================================
Running Frida against charmap.exe
{'type': 'send', 'payload': 'LoadLibraryW,LPCWSTR: MSFTEDIT.DLL'}
{'type': 'send', 'payload': 'LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE'}
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to charmap.exe-raw.log
[*] Writing Potential DLL Sideloading to charmap.exe-sideload.log
--------------------------------------------------
==================================================
Running Frida against mspaint.exe
{'type': 'send', 'payload': 'LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE'}
{'type': 'send', 'payload': 'GetProcAddress,hModule : C:\\WINDOWS\\WinSxS\\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\\gdiplus.dll, LPCSTR: GdiplusStartup'}
{'type': 'send', 'payload': 'LoadLibraryW,LPCWSTR: MSFTEDIT.DLL'}
{'type': 'send', 'payload': 'LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE'}
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
        [-] Potential DllExport Sideloading: GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to mspaint.exe-raw.log
[*] Writing Potential DLL Sideloading to mspaint.exe-sideload.log
--------------------------------------------------
==================================================
[*] Writing dll results to dll_results.csv

WFH COM Hijacking Identification

root@kitploit:~
PS C:\Tools\WFH > python .\wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com
==================================================
Running Frida against C:\Program Files\Internet Explorer\iexplore.exe
--------------------------------------------------
        [+] Potential COM Hijack: Path : HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0E5AAE11-A475-4C5B-AB00-C66DE400274E}\InProcServer32,lpValueName : null,Type : REG_EXPAND_SZ, Value : %SystemRoot%\system32\Windows.Storage.dll
        [+] Potential COM Hijack: Path : HKEY_CLASSES_ROOT\CLSID\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}\InProcServer32,lpValueName : null,Type : REG_SZ, Value : C:\Program Files (x86)\Microsoft\Edge\Application\90.0.818.62\BHO\ie_to_edge_bho_64.dll

[*] Writing raw Frida instrumentation to .\iexplore.exe-raw.log
[*] Writing Potential COM Hijack to .\iexplore.exe-comhijack.log
--------------------------------------------------
==================================================
[*] Writing dll results to comhijack_results.csv

WFH Use Cases

Native Windows Signed Binaries

Kopieren Sie alle nativen Windows-signierten Binärdateien in das wfh-Verzeichnis

root@kitploit:~
Get-ChildItem c:\ -File | ForEach-Object { if($_ -match '.+?exe$') {Get-AuthenticodeSignature $_.fullname} } | where {$_.IsOSBinary} | ForEach-Object {Copy-Item $_.path . }

Suchen Sie nach DLL-Sideloading-Möglichkeiten

root@kitploit:~
python wfh.py -t * -m dll

Suchen Sie nach COM-Hijacking-Möglichkeiten

root@kitploit:~
python wfh.py -t * -m com

Windows Feature Hunter Dridex (WFH Dridex)

Windows Feature Hunter Dridex (WFH Dridex) ist ein Proof-of-Concept-Python-Skript, das vom Dridex-Loader inspiriert ist. WFH Dridex analysiert die Import Address Table (IAT) der Zielausführbaren, kompiliert eine DLL für jeden Eintrag in der IAT der Ausführbaren und validiert, ob ein DLL-Sideload identifiziert wurde.

Die ursprüngliche WFH-Veröffentlichung identifizierte etwa 96 potenzielle DLL-Sideloading-Möglichkeiten. WFH Dridex identifizierte etwa 966 validierte DLL-Sideloading-Möglichkeiten.

WFH Dridex Install

root@kitploit:~
pip install -r requirements.txt

WFH Dridex Dependencies

MingW G++ (64 bit)

g++.exe muss nach der Installation zur Umgebungsvariable PATH hinzugefügt werden, damit WFH Dridex ordnungsgemäß funktioniert.

WFH Dridex Usage

WFH Dridex DLL Sideloading Identification

Zuerst müssen Sie die ausführbaren Dateien, die Sie analysieren möchten, in dasselbe Verzeichnis wie WFH Dridex kopieren.

root@kitploit:~
❯ cp C:\Windows\System32\mspaint.exe .
❯ cp C:\Windows\System32\charmap.exe .
root@kitploit:~
❯ python .\wfh_dridex.py
[*] Creating a payload for charmap.exe with GetUName.dll
    |_ Compiling with: g++.exe -s -Os -static -shared -fpermissive -oGetUName.dll dllmain.c
    |_ Testing charmap.exe with GetUName.dll for DLL sideloading opportunity
    |_ PID: 8936
[>] Listing working DLL sideloads
    |_ charmap.exe GetUName.dll
[*] Creating a payload for mspaint.exe with MFC42u.dll
    |_ Compiling with: g++.exe -s -Os -static -shared -fpermissive testaroo.def -oMFC42u.dll dllmain.c
    |_ Testing mspaint.exe with MFC42u.dll for DLL sideloading opportunity
    |_ PID: 9472
[*] Creating a payload for mspaint.exe with PROPSYS.dll
    |_ Compiling with: g++.exe -s -Os -static -shared -fpermissive -oPROPSYS.dll dllmain.c
    |_ Testing mspaint.exe with PROPSYS.dll for DLL sideloading opportunity
    |_ PID: 11308
[*] Creating a payload for mspaint.exe with WINMM.dll
    |_ Compiling with: g++.exe -s -Os -static -shared -fpermissive -oWINMM.dll dllmain.c
    |_ Testing mspaint.exe with WINMM.dll for DLL sideloading opportunity
    |_ PID: 180
[>] Listing working DLL sideloads
    |_ mspaint.exe MFC42u.dll
    |_ mspaint.exe PROPSYS.dll
    |_ mspaint.exe WINMM.dll

Jetzt können Sie WFH Dridex gegen die ausführbaren Dateien ausführen, um DLL-Sideloading-Möglichkeiten zu identifizieren.

root@kitploit:~
❯ gc .\results.csv
Executable,DllName
charmap.exe,GetUName.dll
mspaint.exe,MFC42u.dll
mspaint.exe,PROPSYS.dll
mspaint.exe,WINMM.dll

WFH Dridex DLL Sideloads from System32

Ein Beispiel-CSV-Ausgabe von WFH Dridex, ausgeführt gegen C:\Windows\System32, kann hier eingesehen werden.

WFH vs WFH Dridex Results

Die ursprüngliche WFH-Veröffentlichung identifizierte etwa 96 potenzielle DLL-Sideloading-Möglichkeiten. WFH Dridex identifizierte etwa 966 validierte DLL-Sideloading-Möglichkeiten.

HijackLibs Contribution

Im Rahmen der WFH Dridex-Veröffentlichung wurde ein Pull-Request an Wietzes HijackLibs-Projekt eingereicht, der 507 neue Einträge in das Projekt aufnahm.

Tool herunterladen