
POC-of-CVE-2022-36271
This is working POC of CVE-2022-36271

This is working POC of CVE-2022-36271


Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of…

Support x86 and x64


CVE-2024-39069

Rust-based DLL hijacking loader for MobaXterm (CVE-2026-6421) with persistence

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Lightweight native Windows memory scanner for AV/EDR platforms, detecting suspicious mapped images and manual DLL injection techniques by IAT thunk

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

Reflective PE packer.

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.


Microsoft signed ActiveDirectory PowerShell module

Robber is open source tool for finding executables prone to DLL hijacking