Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
DLLHijackHunter — Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths. | Kitploit
Tools/GitHubGitHub/ghostvectoracademy/dllhijackhunter
Privilege EscalationVulnerability ScannersPayload GenerationPersistence MechanismsDynamic Code Analysis (DAST)ExploitationLateral MovementPenetration TestingBinary Analysis

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Learning & Education
Red Teaming
GitHubghostvectoracademy/dllhijackhunter

DLLHijackHunter

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

View Repository
396443812 days agoReviewed by Kitploit

DLLHijackHunter

By ProjectMerai

Automated DLL Hijacking Discovery, Validation, and Confirmation
Turning local misconfigurations into weaponized, confirmed attack paths.


Overview

DLLHijackHunter is an automated Windows DLL hijacking detection tool that goes beyond static analysis. It discovers, validates, and confirms DLL hijacking opportunities using a multi-phase pipeline:

  1. Discovery — Enumerates binaries across services, scheduled tasks, startup items, COM objects, and AutoElevate UAC bypass vectors
  2. Filtration — Eliminates false positives through intelligent hard and soft gates
  3. Canary Confirmation — Deploys a harmless canary DLL and triggers the binary to prove the hijack works
  4. Scoring & Reporting — Ranks findings by exploitability with a tiered confidence system

Most DLL hijacking tools stop at “this DLL might be hijackable.” DLLHijackHunter attempts to validate it, cross-reference it against known exploit intelligence, and confirm real execution paths where possible.


Architecture

flowchart TB
    subgraph Phase1["Phase 1: Discovery"]
        SE["Static Engine<br/>Services, Tasks, Startup,<br/>COM, Run Keys"]
        AE["AutoElevate Engine<br/>Manifest + COM UAC Bypass"]
        PE["PE Analyzer<br/>Import Tables, Delay Loads,<br/>Manifests, Exports"]
        ETW["ETW Engine<br/>Real-time DLL Load<br/>Monitoring"]
        SO["Search Order<br/>Calculator"]
    end

    subgraph Phase2["Phase 2: Filter Pipeline"]
        direction LR
        HG["Hard Gates<br/>(Binary Kill)"]
        SG["Soft Gates<br/>(Confidence Adj.)"]
    end

    subgraph Phase3["Phase 3: Load Verification (--verify-load)"]
        LP["LoadProbe<br/>Child-process loader test<br/>Probe DLL placed &amp; removed"]
    end

    subgraph Phase4["Phase 4: Canary"]
        CB["Canary DLL Builder"]
        TE["Trigger Executor"]
        VF["Verification"]
    end

    subgraph Phase5["Phase 5: Output"]
        SC["Tiered Scorer"]
        RC["Console Report"]
        RJ["JSON Report"]
        RH["HTML Report"]
    end

    SE --> PE --> SO
    AE --> PE
    ETW --> SO
    SO --> Phase2
    HG --> SG
    Phase2 --> Phase3
    Phase3 --> Phase4
    CB --> TE --> VF
    Phase4 --> Phase5

Key Features

Hijack Type Coverage

TypeDescriptionStealthStatus
PhantomDLL doesn't exist anywhere on diskHighImplemented
Search OrderPlace DLL earlier in the Windows search orderHighImplemented
Side-LoadingAbuse legitimate app loading DLLs from its directoryHighImplemented (AutoElevate copy-to-temp path)
.local RedirectHijack via .local directory redirectionHighImplemented
ENV PATHWeaponization of writable directories in system PATHHighImplemented (curated service/DLL map)
AppInit DLLsAppInit_DLLs registry abuseLowImplemented
AppCert DLLsAppCertDLLs registry abuse (loads into every CreateProcess/WinExec caller)LowImplemented
CWDCurrent Working Directory hijackLowPlanned — not currently produced by any discovery path

IFEO Debugger entries are enumerated and the referenced binary is analyzed for DLL imports, but there is no dedicated IFEO/KnownDLL-bypass hijack type — those are not advertised as standalone detections.

UAC Bypass Discovery

DLLHijackHunter includes dedicated UAC bypass discovery:

  • Manifest AutoElevate — Scans System32 and SysWOW64 for EXEs with <autoElevate>true</autoElevate> in embedded manifests
  • COM AutoElevation — Scans HKLM\SOFTWARE\Classes\CLSID for COM objects with Elevation\Enabled=1
  • Side-Load Simulation — For AutoElevate binaries that do not call SetDllDirectory or SetDefaultDllDirectories, simulates the “copy EXE to writable folder + drop DLL” attack path

Targeted Vulnerability Knowledge Base

  • Targeted vulnerability mapping — Cross-references discovered imports against a bundled snapshot of the HijackLibs dataset (≈590 documented DLL entries spanning ≈700 vulnerable executables), embedded as Resources/hijacklibs.json. A match boosts confidence and links the finding to its HijackLibs reference page; the absence of a match means nothing. The dataset is data-driven — refresh it by re-downloading https://hijacklibs.net/api/hijacklibs.json over that resource (no code changes required). Dataset © the HijackLibs project and contributors.
  • Automated PATH exploitation — Evaluates writable PATH folders and generates hijack candidates for a curated map of native Windows services known to search PATH for missing DLLs
  • Expanded phantom DLL hunting — Searches for a library of high-value phantom DLL opportunities across multiple categories

Filter Pipeline

The pipeline reduces false positives through two stages:

Hard Gates

  • API set schema filtering (api-ms-*, ext-ms-*)
  • KnownDLL filtering
  • Attacker-relative ACL writability validation — a path counts as writable only if an unprivileged principal (Users / Authenticated Users / Everyone, plus leak-proof sub-admin service accounts like LOCAL SERVICE/NETWORK SERVICE) has effective write rights. Crucially, this is computed independently of the token the tool runs under, so running elevated does not make System32/Program Files look writable. This is what makes elevated runs meaningful for LPE triage.

Soft Gates

  • WinSxS manifest penalty
  • Privilege delta analysis
  • LoadLibraryEx mitigation checks
  • Signature validation checks
  • Graceful error-handling penalties

Canary Confirmation

Instead of guessing, DLLHijackHunter attempts to prove hijacks work:

sequenceDiagram
    participant H as DLLHijackHunter
    participant B as Canary DLL Builder
    participant T as Trigger Executor
    participant V as Victim Binary

    H->>B: Build canary DLL
    B->>B: Extract precompiled canary<br/>(or compile a proxy with MSVC)
    B-->>H: canary.dll + confirmation file path
    H->>H: Place DLL at hijack path
    H->>T: Trigger binary execution
    T->>V: Start service / run task / COM activate
    V->>V: Loads canary DLL
    V-->>H: Writes confirmation file<br/>PID, privilege, integrity level
    H->>H: Record: CONFIRMED
    H->>H: Cleanup canary DLL
Download Tool