
Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.
Automated DLL Hijacking Discovery, Validation, and Confirmation
Turning local misconfigurations into weaponized, confirmed attack paths.
DLLHijackHunter is an automated Windows DLL hijacking detection tool that goes beyond static analysis. It discovers, validates, and confirms DLL hijacking opportunities using a multi-phase pipeline:
Most DLL hijacking tools stop at “this DLL might be hijackable.” DLLHijackHunter attempts to validate it, cross-reference it against known exploit intelligence, and confirm real execution paths where possible.
flowchart TB
subgraph Phase1["Phase 1: Discovery"]
SE["Static Engine<br/>Services, Tasks, Startup,<br/>COM, Run Keys"]
AE["AutoElevate Engine<br/>Manifest + COM UAC Bypass"]
PE["PE Analyzer<br/>Import Tables, Delay Loads,<br/>Manifests, Exports"]
ETW["ETW Engine<br/>Real-time DLL Load<br/>Monitoring"]
SO["Search Order<br/>Calculator"]
end
subgraph Phase2["Phase 2: Filter Pipeline"]
direction LR
HG["Hard Gates<br/>(Binary Kill)"]
SG["Soft Gates<br/>(Confidence Adj.)"]
end
subgraph Phase3["Phase 3: Load Verification (--verify-load)"]
LP["LoadProbe<br/>Child-process loader test<br/>Probe DLL placed & removed"]
end
subgraph Phase4["Phase 4: Canary"]
CB["Canary DLL Builder"]
TE["Trigger Executor"]
VF["Verification"]
end
subgraph Phase5["Phase 5: Output"]
SC["Tiered Scorer"]
RC["Console Report"]
RJ["JSON Report"]
RH["HTML Report"]
end
SE --> PE --> SO
AE --> PE
ETW --> SO
SO --> Phase2
HG --> SG
Phase2 --> Phase3
Phase3 --> Phase4
CB --> TE --> VF
Phase4 --> Phase5
| Type | Description | Stealth | Status |
|---|---|---|---|
| Phantom | DLL doesn't exist anywhere on disk | High | Implemented |
| Search Order | Place DLL earlier in the Windows search order | High | Implemented |
| Side-Loading | Abuse legitimate app loading DLLs from its directory | High | Implemented (AutoElevate copy-to-temp path) |
| .local Redirect | Hijack via .local directory redirection | High | Implemented |
| ENV PATH | Weaponization of writable directories in system PATH | High | Implemented (curated service/DLL map) |
| AppInit DLLs | AppInit_DLLs registry abuse | Low | Implemented |
| AppCert DLLs | AppCertDLLs registry abuse (loads into every CreateProcess/WinExec caller) | Low | Implemented |
| CWD | Current Working Directory hijack | Low | Planned — not currently produced by any discovery path |
IFEO Debugger entries are enumerated and the referenced binary is analyzed for DLL imports, but there is no dedicated IFEO/KnownDLL-bypass hijack type — those are not advertised as standalone detections.
DLLHijackHunter includes dedicated UAC bypass discovery:
System32 and SysWOW64 for EXEs with <autoElevate>true</autoElevate> in embedded manifestsHKLM\SOFTWARE\Classes\CLSID for COM objects with Elevation\Enabled=1SetDllDirectory or SetDefaultDllDirectories, simulates the “copy EXE to writable folder + drop DLL” attack pathResources/hijacklibs.json. A match boosts confidence and links the finding to its HijackLibs reference page; the absence of a match means nothing. The dataset is data-driven — refresh it by re-downloading https://hijacklibs.net/api/hijacklibs.json over that resource (no code changes required). Dataset © the HijackLibs project and contributors.PATH folders and generates hijack candidates for a curated map of native Windows services known to search PATH for missing DLLsThe pipeline reduces false positives through two stages:
Hard Gates
api-ms-*, ext-ms-*)Users / Authenticated Users / Everyone, plus leak-proof sub-admin service accounts like LOCAL SERVICE/NETWORK SERVICE) has effective write rights. Crucially, this is computed independently of the token the tool runs under, so running elevated does not make System32/Program Files look writable. This is what makes elevated runs meaningful for LPE triage.Soft Gates
LoadLibraryEx mitigation checksInstead of guessing, DLLHijackHunter attempts to prove hijacks work:
sequenceDiagram
participant H as DLLHijackHunter
participant B as Canary DLL Builder
participant T as Trigger Executor
participant V as Victim Binary
H->>B: Build canary DLL
B->>B: Extract precompiled canary<br/>(or compile a proxy with MSVC)
B-->>H: canary.dll + confirmation file path
H->>H: Place DLL at hijack path
H->>T: Trigger binary execution
T->>V: Start service / run task / COM activate
V->>V: Loads canary DLL
V-->>H: Writes confirmation file<br/>PID, privilege, integrity level
H->>H: Record: CONFIRMED
H->>H: Cleanup canary DLL