Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
DylibHijackTest — Discover DYLD_INSERT_LIBRARIES hijacks on macOS | Kitploit
Tools/GitHubGitHub/slyd0g/dylibhijacktest
Privilege EscalationDynamic Analysis (Sandboxing)Persistence MechanismsBinary AnalysisRed Teaming
GitHubslyd0g/dylibhijacktest

DylibHijackTest

Discover DYLD_INSERT_LIBRARIES hijacks on macOS

View Repository
458184 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

DylibHijackTest

inspect.py

Requirements

  • Install Python3 requirements: pip3 install -r requirements.txt
  • Compile dylib from source because don't trust compiled things from GitHub: gcc -dynamiclib DylibHijackTest.c -o DylibHijackTest.dylib

How it Works

⚠️ This will spawn many processes on your machine, run this in a VM: Be very careful here!

  • inject.py
    • Recursively crawl a folder and search for Mach-O binaries with MH_EXECUTE header
    • Start the Mach-O binary with DYLD_INSERT_LIBRARIES environment variable pointed at our malicious dylib
    • Redirect all stdout to a file and stderr to /dev/null
  • inspect.py
    • Take text file output from inject.py to see what Mach-Os ary injectable and use codesign to check for useful entitlements
    • Party!!!

Usage

$ python3 inject.py /Applications/iMovie.app /Users/slyd0g/DylibHijackTest.dylib > imovie.txt 2> /dev/null
$ python3 inspect.py /Users/slyd0g/Projects/DylibHijackTest/imovie.txt
Download Tool