Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
WFH — Frida-basiertes dynamisches Analysewerkzeug, das automatisch DLL-Sideloading- und COM-Hijacking-Schwachstellen in Windows-Ausführbaren Dateien durch Laufzeitinstrumentierung und IAT-Analyse identifiziert. | Kitploit
Tools/GitHubGitHub/conscioushacker/wfh
Dynamische Analyse (Sandboxing)ExploitationFuzzingBinäranalyse
GitHubconscioushacker/wfh

WFH

Frida-basiertes dynamisches Analysewerkzeug, das automatisch DLL-Sideloading- und COM-Hijacking-Schwachstellen in Windows-Ausführbaren Dateien durch Laufzeitinstrumentierung und IAT-Analyse identifiziert.

Repository anzeigen
4367213vor 4 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

Windows Feature Hunter (WFH)

Windows Feature Hunter (WFH) ist ein Proof-of-Concept-Python-Skript, das Frida, ein dynamisches Instrumentierungs-Toolkit, verwendet, um bei der potenziellen Identifizierung von allgemeinen „Schwachstellen“ oder „Features“ in Windows-Ausführbaren zu helfen. WFH hat derzeit die Fähigkeit, potenzielle Dynamic Linked Library (DLL)-Sideloading- und Component Object Model (COM)-Hijacking-Möglichkeiten im großen Maßstab automatisch zu identifizieren.

DLL-Sideloading nutzt die Windows Side-by-Side (WinSXS)-Assembly, um eine bösartige DLL aus der Side-by-Side (SXS)-Auflistung zu laden. COM-Hijacking ermöglicht es einem Angreifer, bösartigen Code einzuschleusen, der anstelle legitimer Software ausgeführt werden kann, indem die COM-Referenzen und -Beziehungen gekapert werden. WFH gibt die potenziellen Schwachstellen aus und schreibt eine CSV-Datei, die die potenziellen Schwachstellen in den Ziel-Windows-Ausführbaren enthält.

Table of Contents

  • Windows Feature Hunter (WFH)
    • WFH Install
    • WFH Help
    • WFH Usage
      • WFH DLL Sideloading Identification
      • WFH COM Hijacking Identification
    • WFH Use Cases
      • Native Windows Signed Binaries
  • Windows Feature Hunter Dridex (WFH Dridex)
    • WFH Dridex Install
    • WFH Dridex Dependencies
    • WFH Dridex Usage
      • WFH Dridex DLL Sideloading Identification
    • WFH Dridex DLL Sideloads from System32
      • WFH vs WFH Dridex Results
  • HijackLibs Contribution

WFH Install

pip install -r requirements.txt

WFH Help

PS C:\Tools\WFH > python .\wfh.py -h
usage: wfh.py [-h] -t T [T ...] -m {dll,com} [-v] [-timeout TIMEOUT]

Windows Feature Hunter

optional arguments:
  -h, --help            show this help message and exit
  -t T [T ...], -targets T [T ...]
                        list of target windows executables
  -m {dll,com}, -mode {dll,com}
                        vulnerabilities to potentially identify
  -v, -verbose          verbose output from Frida instrumentation
  -timeout TIMEOUT      timeout value for Frida instrumentation

EXAMPLE USAGE
    NOTE: It is recommended to copy target binaries to the same directory as wfh for identifying DLL Sideloading

    DLL Sideloading Identification (Single):        python wfh.py -t .\mspaint.exe -m dll
    DLL Sideloading Identification (Verbose):       python wfh.py -t .\mspaint.exe -m dll -v
    DLL Sideloading Identification (Timeout 30s):   python wfh.py -t .\mspaint.exe -m dll -timeout 30
    DLL Sideloading Identification (Wildcard):      python wfh.py -t * -m dll
    DLL Sideloading Identification (List):          python wfh.py -t .\mspaint.exe .\charmap.exe -m dll

    COM Hijacking Identification (Single):          python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com
    COM Hijacking Identification (Verbose):         python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com -v
    COM Hijacking Identification (Timeout 60s):     python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com -timeout 60
    COM Hijacking Identification (Wildcard):        python wfh.py -t * -m com -v
    COM Hijacking Identification (List):            python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" "C:\Windows\System32\notepad.exe" -m com -v

WFH Usage

WFH DLL Sideloading Identification

Zuerst müssen Sie die ausführbaren Dateien, die Sie analysieren möchten, in dasselbe Verzeichnis wie WFH kopieren.

PS C:\Tools\WFH > copy C:\Windows\System32\mspaint.exe .
PS C:\Tools\WFH > copy C:\Windows\System32\charmap.exe .
PS C:\Tools\WFH > dir


    Directory: C:\Tools\WFH


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         5/14/2021   2:12 PM                .vscode
-a----          5/6/2021   2:39 PM           1928 .gitignore
-a----         12/7/2019   2:09 AM         198656 charmap.exe
-a----         5/18/2021   7:39 AM           6603 loadlibrary.js
-a----          4/7/2021  12:48 PM         988160 mspaint.exe
-a----         5/18/2021   7:53 AM           8705 README.md
-a----         5/17/2021  11:27 AM           5948 registry.js
-a----          5/6/2021   2:41 PM             11 requirements.txt
-a----         5/18/2021   8:35 AM          10623 wfh.py

Jetzt können Sie wfh gegen die ausführbaren Dateien ausführen, um DLL-Sideloading-Möglichkeiten zu identifizieren.

PS C:\Tools\WFH > python .\wfh.py -t * -m dll
==================================================
Running Frida against charmap.exe
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to charmap.exe-raw.log
[*] Writing Potential DLL Sideloading to charmap.exe-sideload.log
--------------------------------------------------
==================================================
Running Frida against mspaint.exe
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
        [-] Potential DllExport Sideloading: GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to mspaint.exe-raw.log
[*] Writing Potential DLL Sideloading to mspaint.exe-sideload.log
--------------------------------------------------
==================================================
[*] Writing dll results to dll_results.csv

PS C:\Tools\WFH > type .\dll_results.csv
Executable,WinAPI,DLL,EntryPoint / WinAPI Args
charmap.exe,LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
charmap.exe,LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE
mspaint.exe,LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
mspaint.exe,GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
mspaint.exe,LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
mspaint.exe,LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

Wenn Sie eine ausführlichere Ausgabe bevorzugen, können Sie "-v" verwenden, um jede Nachricht von Frida zu sehen, das die Windows-API-Aufrufe instrumentiert. Sie können diese Ausgabe auch in der Rohprotokolldatei anzeigen.

PS C:\Tools\WFH > python .\wfh.py -t * -m dll -v
==================================================
Running Frida against charmap.exe
{'type': 'send', 'payload': 'LoadLibraryW,LPCWSTR: MSFTEDIT.DLL'}
{'type': 'send', 'payload': 'LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE'}
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE
Tool herunterladen