Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Crassus — Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths, automatically generating proxy DLL source code. | Kitploit
Tools/GitHubGitHub/vu-ls/crassus
Privilege EscalationExploitationPenetration TestingBinary Analysis
GitHubvu-ls/crassus

Crassus

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths, automatically generating proxy DLL source code.

View Repository
63364607 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Crassus Windows privilege escalation discovery tool

Quick start

  1. In Process Monitor, select the Enable Boot Logging option. "Process Monitor Boot Logging option"
  2. Reboot.
  3. Once you have logged in and Windows has settled, run Process Monitor once again.
  4. When prompted, save the boot log, e.g., to raw.PML.
  5. Reset the default Process Monitor filter using Ctrl-R.
  6. Save this log file, e.g., to boot.PML.
  7. Run Crassus.exe boot.PML.
  8. Investigate any green colored results and the corresponding entries in results.csv.

Table of Contents

  • Why "Crassus"
    • Did you really make yet another privilege escalation discovery tool?
    • Features
    • Flowchart
  • Screenshots
    • Crassus Execution
    • CSV Output
    • Exports
    • Export DLL Functions
    • Export DLL Ordinals
  • Getting Crassus.exe
    • Building with Visual studio
    • Using precompiled Crassus.exe
  • Usage
    • Execution Flow
    • Command Line Arguments
    • Examples
    • Proxy DLL Template
    • openssl.cnf Template
  • Compiling Proxy DLLs
    • Visual Studio
    • MinGW
  • Real World Examples
    • Acronis True Image
    • Atlassian Bitbucket
    • McAfee
    • Microsoft SQL Server 2022
  • Troubleshooting
    • Missing files not loaded
    • Code executed with unexpected privileges
    • Findings disappear on reboot
  • Contributions
  • Credits

Why "Crassus"?

Accenture made a tool called Spartacus, which finds DLL hijacking opportunities on Windows. Using Spartacus as a starting point, we created Crassus to extend Windows privilege escalation finding capabilities beyond simply looking for missing files. The ACLs used by files and directories of privileged processes can find more than just looking for missing files to achieve the goal.

Did you really make yet another privilege escalation discovery tool?

...but with a twist as Crassus is utilizing the SysInternals Process Monitor and is parsing raw PML log files. Typical usage is to generate a boot log using Process Monitor and then parse it with Crassus. It will also automatically generate source code for proxy DLLs with all relevant exports for vulnerable DLLs.

Features

  • Parsing ProcMon PML files natively. The log (PML) parser has been implemented by porting partial functionality to C# from https://github.com/eronnen/procmon-parser/. You can find the format specification here.
  • Crassus will create source code for proxy DLLs for all missing DLLs that were identified. For instance, if an application is vulnerable to DLL Hijacking via version.dll, Crassus will create version.cpp and version.def files for you with all the exports included in it. By default the proxy DLLs will launch calc.exe. Build scripts are included to build the DLLs on Visual Studio or MinGW.
  • For other events of interest, such as creating a process or loading a library, the ability for unprivileged users to modify the file or any parts of the path to the file is investigated.
  • Able to process large PML files and store all events of interest in an output CSV file.

Flowchart

The general gist of how Crassus works can be summarized in this flowchart: Crassus flowchart

Screenshots

Crassus Execution

Running Crassus

CSV Output

CSV Output

Output Exports

Exports

Export DLL Functions

DLL Functions

Export DLL Ordinals

DLL Ordinals

Getting Crassus.exe

Building with Visual Studio

Crassus was developed as a Visual Studio 2019 project. To build Crassus.exe:

  1. Open Crassus.sln
  2. Press Ctrl+Shift+B on your keyboard

Using precompiled Crassus.exe

If you trust running other people's code without knowing what it does, Crassus.exe is provided in this repository.

Usage

Execution Flow

  1. In Process Monitor, select the Enable Boot Logging option. "Process Monitor Boot Logging option"
  2. Reboot.
  3. Once you have logged in and Windows has settled, optionally also run scheduled tasks that may be configured to run with privileges.
  4. Run Process Monitor once again.
  5. When prompted, save the boot log.
  6. Reset the default Process Monitor filter using Ctrl-R.
  7. Save this log file, e.g., to boot.PML. The reason for re-saving the log file is twofold:
    1. Older versions of Process Monitor do not save boot logs as a single file.
    2. Boot logs by default will be unfiltered, which may contain extra noise, such as a local-user DLL hijacking in the launching of of Process Monitor itself.

Command Line Arguments

ArgumentDescription
<PMLFILE>Location (file) of the existing ProcMon event log file.
--verboseEnable verbose output.
--debugEnable debug output.

Examples

Parse the Process Monitor boot log saved in boot.PML. All vulnerable paths will be saved as results.csv and all proxy DLL source files in the stubs subdirectory.

C:\tmp> Crassus.exe boot.PML

Proxy DLL Template

Download Tool