
Robber
Robber is open source tool for finding executables prone to DLL hijacking

Robber is open source tool for finding executables prone to DLL hijacking

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

PowerSploit - A PowerShell Post-Exploitation Framework

C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be…

Bypass UAC by hijacking a DLL located in the Native Image Cache

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

DLL Injection tool to unlock guest VMs

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

RemoteDLLInjector

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

We found a way to DLL sideload with cleanmgr.exe

Panoramic Dental Imaging software Stealthy Privilege Escalation Vulnerability

SeriousSAM Auto Exploiter

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

Seagate Toolkit for Windows (Installer <2.35.0.6) is vulnerable to insecure DLL loading. The installer loads DLLs from the working directory without…

Code Execution & Persistence in NETWORK SERVICE FAX Service

A C2 post-exploitation framework