
DLLHSC
Automated scanner for discovering DLL search order hijacking candidates in Windows executables, featuring import table parsing, runtime module…

Automated scanner for discovering DLL search order hijacking candidates in Windows executables, featuring import table parsing, runtime module…

Yet another PoC for https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows

Parses Cortex XDR agent database lock files to extract agent settings, uninstall password hash/salt, and security exclusions for red team assessments…

DLL Password Filter Implant with Exfiltration Capabilities

AAD related enumeration in Nim

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

CompMgmtLauncher & Sharepoint DLL Search Order hijacking UAC/persist via OneDrive

Modular framework for Windows UAC bypass attacks and mitigation, featuring DLL hijacking, fileless execution, and real-time monitoring to detect and…

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.


CVE-2018-8440 standalone exploit

Adaptive DLL hijacking / dynamic export forwarding - EAT preserve

A Bumblebee-inspired Crypter

A session-0 capable dll injection utility