
DLLHijackingScanner
This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification.

This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification.


CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM

PowerSploit - A PowerShell Post-Exploitation Framework

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

New version of RottenPotato as a C++ DLL and standalone C++ binary - no need for meterpreter or other tools.

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Robber is open source tool for finding executables prone to DLL hijacking

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be…

A C2 post-exploitation framework

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

A Bind Shell Using the Fax Service and a DLL Hijack

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.

Activation Context Hijacking Evasion Tool