Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Anvil — Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers conducting targeted application security assessments. It covers multiple attack classes in a single targeted run. | Kitploit
Tools/GitHubGitHub/shellkraft/anvil
Privilege EscalationReconnaissanceVulnerability AnalysisExploitationPost-ExploitationPenetration TestingBinary AnalysisRed Teaming
GitHubshellkraft/anvil

Anvil

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers conducting targeted application security assessments. It covers multiple attack classes in a single targeted run.

374166 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

logo


Runtime-first privilege escalation and attack surface assessment for Windows thick clients.

Anvil is a runtime-first privilege escalation and attack surface assessment tool for Windows thick client applications. Rather than scanning the filesystem blindly, it pairs Procmon capture with Windows AccessCheck to report only paths that are both observed at runtime and confirmed writable by standard users, eliminating the false positive noise that plagues generic enumeration tools.


Contents

  • Key Features
  • How It Works
  • Modules
  • Requirements
  • Sysinternals Tools
  • Installation
  • Distribution
  • Usage
  • Examples
  • Output
  • Severity Model
  • Filters
  • Disclaimer

Key Features

Most thick client assessment tools cover one or two attack classes. Anvil is built around the idea that runtime observation, ACL-verified exploitability, and a wide attack surface should all live in the same targeted run — with a gated pipeline that keeps the output actionable.

False-Positive Pipeline

Every candidate passes four sequential gates before it is reported.

Hard Gates

  • Process integrity must be High or SYSTEM IL
  • Path must not be inside System32, SysWOW64, or Program Files
  • Directory writable by a standard user — verified via Windows AccessCheck API

Module Logic Gates

  • Symlink: disposition flags (Supersede, OverwriteIf, etc.) + cross-user writability guard
  • COM: registry CLSID correlated back to a missing or writable DLL path
  • Binary: PATH ordering checked — writable entries appearing before System32 only
  • Unquoted path: intermediate phantom directories confirmed writable, kernel .sys paths excluded

How It Works

  1. Target Resolution
    The tool resolves the target to an executable path (from --exe, --service, or --pid). If it is a service, ServiceInfo is retrieved with current PID and state.

  2. Procmon Capture

    • For a service, Procmon is started, then the service is cleanly restarted (with state‑transition waits). The new PID is captured.
    • For a regular EXE, the process is launched at Medium integrity (using a duplicated Explorer token) to simulate a standard user. The PID is recorded.

    Process integrity level is read immediately after launch (while the process is alive) and stored in the context.

  3. Per‑Module Filtered Analysis
    Each module requests a filtered CSV export from Procmon using its own .pmc filter (stored in filters/). The CSV is parsed, and a series of gates are applied:

    • Integrity ≥ High
    • Path not in a protected system directory
    • Directory writable by a standard user (AccessCheck)
    • Additional module‑specific logic (e.g., disposition for symlinks, registry‑to‑file correlation for COM)
  4. Static Correlation
    The com module performs an additional static pass — scanning the target binary for embedded CLSIDs and checking each against HKLM and HKCU — to surface hijack opportunities not exercised during the capture window. These are flagged with a [Static Correlation] tag.

  5. Reporting
    Findings are printed to the terminal (with colour coding) and optionally written to JSON or a standalone HTML report.


Architecture

flowchart TB
    %% Phase 1
    subgraph Phase1["Phase 1: Target & Runtime Discovery"]
        TR["Target Resolver<br/>--exe / --service / --pid"] -->
        IL["Integrity Gate<br/>Medium-IL launch / Service restart"] -->
        PM["Procmon Engine<br/>Runtime FS / Reg / Pipe events"]
    end

    %% Phase 2
    subgraph Phase2["Phase 2: Signal Reduction"]
        direction LR
        PF["Per-Module PMC Filters<br/>High-signal traces only"] -->
        CSV["Filtered CSV Export"]
    end

    %% Phase 3
    subgraph Phase3["Phase 3: Exploitability Gates"]
        HG["Hard Gates<br/>High-Integrity target<br/>Not protected path"] -->
        ACL["AccessChk Validation<br/>Writable by standard user"] -->
        LG["Logic Gates<br/>Module-specific rules"]
    end

    %% Phase 4
    subgraph Phase4["Phase 4: Correlation"]
        RT["Runtime Findings"]
        ST["Static Correlation<br/>COM: CLSID binary scan / registry"]
    end

    %% Phase 5
    subgraph Phase5["Phase 5: Reporting"]
        SV["Severity Engine<br/>P1–P5"] --> OUT["Console Output"]
        SV --> JSON["JSON Report"]
        SV --> HTML["HTML Report"]
    end

    %% Cross-phase flow
    PM --> PF
    CSV --> HG
    LG --> RT
    ST -.-> RT
    RT --> SV

    %% Styling
    classDef p1 fill:#0f2a44,stroke:#4cc9f0,color:#e6f1ff
    classDef p2 fill:#2b193d,stroke:#f72585,color:#fde8f3
    classDef p3 fill:#1f2d1c,stroke:#7ae582,color:#eaf7ea
    classDef p4 fill:#3a1f1f,stroke:#ffb703,color:#fff3d6
    classDef p5 fill:#0b2e2a,stroke:#00f5d4,color:#e6fffb

    class Phase1 p1
    class Phase2 p2
    class Phase3 p3
    class Phase4 p4
    class Phase5 p5
    linkStyle default stroke:#9aa4b2,stroke-width:2px

Comparison

Download Tool