Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
WFH — Ferramenta de análise dinâmica baseada em Frida que identifica automaticamente vulnerabilidades de sideloading de DLL e sequestro de COM em executáveis Windows por meio de instrumentação em tempo de execução e análise de IAT. | Kitploit
Ferramentas/GitHubGitHub/conscioushacker/wfh
Análise Dinâmica (Sandboxing)ExploraçãoFuzzingAnálise de Binários
GitHubconscioushacker/wfh

WFH

Ferramenta de análise dinâmica baseada em Frida que identifica automaticamente vulnerabilidades de sideloading de DLL e sequestro de COM em executáveis Windows por meio de instrumentação em tempo de execução e análise de IAT.

Ver Repositório
4367213há 4 anosRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

Windows Feature Hunter (WFH)

Windows Feature Hunter (WFH) é um script python de prova de conceito que usa Frida, um toolkit de instrumentação dinâmica, para auxiliar na identificação potencial de “vulnerabilidades” ou “funcionalidades” comuns em executáveis do Windows. Atualmente, o WFH tem a capacidade de identificar automaticamente potenciais oportunidades de carregamento lateral de DLL (Dynamic Linked Library) e de sequestro de COM (Component Object Model) em escala.

O carregamento lateral de DLL utiliza o assembly lado a lado do Windows (WinSXS) para carregar uma DLL maliciosa a partir da listagem lado a lado (SXS). O sequestro de COM permite que um adversário insira código malicioso que pode ser executado no lugar de software legítimo, sequestrando as referências e relacionamentos COM. O WFH exibirá as potenciais vulnerabilidades e escreverá um arquivo CSV contendo as potenciais vulnerabilidades nos executáveis do Windows alvo.

Table of Contents

  • Windows Feature Hunter (WFH)
    • Instalação do WFH
    • Ajuda do WFH
    • Uso do WFH
      • Identificação de Carregamento Lateral de DLL pelo WFH
      • Identificação de Sequestro de COM pelo WFH
    • Casos de Uso do WFH
      • Binários Nativos do Windows Assinados
  • Windows Feature Hunter Dridex (WFH Dridex)
    • Instalação do WFH Dridex
    • Dependências do WFH Dridex
    • Uso do WFH Dridex
      • Identificação de Carregamento Lateral de DLL pelo WFH Dridex
    • Carregamentos Laterais de DLL do WFH Dridex a partir do System32
      • Resultados: WFH vs WFH Dridex
  • Contribuição para o HijackLibs

Instalação do WFH

pip install -r requirements.txt

Ajuda do WFH

PS C:\Tools\WFH > python .\wfh.py -h
usage: wfh.py [-h] -t T [T ...] -m {dll,com} [-v] [-timeout TIMEOUT]

Windows Feature Hunter

optional arguments:
  -h, --help            show this help message and exit
  -t T [T ...], -targets T [T ...]
                        list of target windows executables
  -m {dll,com}, -mode {dll,com}
                        vulnerabilities to potentially identify
  -v, -verbose          verbose output from Frida instrumentation
  -timeout TIMEOUT      timeout value for Frida instrumentation

EXAMPLE USAGE
    NOTE: It is recommended to copy target binaries to the same directory as wfh for identifying DLL Sideloading

    DLL Sideloading Identification (Single):        python wfh.py -t .\mspaint.exe -m dll
    DLL Sideloading Identification (Verbose):       python wfh.py -t .\mspaint.exe -m dll -v
    DLL Sideloading Identification (Timeout 30s):   python wfh.py -t .\mspaint.exe -m dll -timeout 30
    DLL Sideloading Identification (Wildcard):      python wfh.py -t * -m dll
    DLL Sideloading Identification (List):          python wfh.py -t .\mspaint.exe .\charmap.exe -m dll

    COM Hijacking Identification (Single):          python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com
    COM Hijacking Identification (Verbose):         python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com -v
    COM Hijacking Identification (Timeout 60s):     python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" -m com -timeout 60
    COM Hijacking Identification (Wildcard):        python wfh.py -t * -m com -v
    COM Hijacking Identification (List):            python wfh.py -t "C:\Program Files\Internet Explorer\iexplore.exe" "C:\Windows\System32\notepad.exe" -m com -v

Uso do WFH

Identificação de Carregamento Lateral de DLL pelo WFH

Primeiro você precisa copiar os binários que deseja analisar para o mesmo diretório do WFH

PS C:\Tools\WFH > copy C:\Windows\System32\mspaint.exe .
PS C:\Tools\WFH > copy C:\Windows\System32\charmap.exe .
PS C:\Tools\WFH > dir


    Directory: C:\Tools\WFH


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         5/14/2021   2:12 PM                .vscode
-a----          5/6/2021   2:39 PM           1928 .gitignore
-a----         12/7/2019   2:09 AM         198656 charmap.exe
-a----         5/18/2021   7:39 AM           6603 loadlibrary.js
-a----          4/7/2021  12:48 PM         988160 mspaint.exe
-a----         5/18/2021   7:53 AM           8705 README.md
-a----         5/17/2021  11:27 AM           5948 registry.js
-a----          5/6/2021   2:41 PM             11 requirements.txt
-a----         5/18/2021   8:35 AM          10623 wfh.py

Agora você pode executar o wfh contra os binários para identificar oportunidades de carregamento lateral de DLL

PS C:\Tools\WFH > python .\wfh.py -t * -m dll
==================================================
Running Frida against charmap.exe
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to charmap.exe-raw.log
[*] Writing Potential DLL Sideloading to charmap.exe-sideload.log
--------------------------------------------------
==================================================
Running Frida against mspaint.exe
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
        [-] Potential DllExport Sideloading: GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

[*] Writing raw Frida instrumentation to mspaint.exe-raw.log
[*] Writing Potential DLL Sideloading to mspaint.exe-sideload.log
--------------------------------------------------
==================================================
[*] Writing dll results to dll_results.csv

PS C:\Tools\WFH > type .\dll_results.csv
Executable,WinAPI,DLL,EntryPoint / WinAPI Args
charmap.exe,LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
charmap.exe,LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE
mspaint.exe,LoadLibraryExW,LPCWSTR : gdiplus.dll, dwFlags : NONE
mspaint.exe,GetProcAddress,hModule : C:\WINDOWS\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.789_none_faf0a7e97612e7bb\gdiplus.dll, LPCSTR: GdiplusStartup
mspaint.exe,LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
mspaint.exe,LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE

Se preferir uma saída mais detalhada, você pode usar "-v" para ver todas as mensagens do Frida instrumentando as chamadas da API do Windows. Você também pode visualizar essa saída no arquivo de log bruto.

PS C:\Tools\WFH > python .\wfh.py -t * -m dll -v
==================================================
Running Frida against charmap.exe
{'type': 'send', 'payload': 'LoadLibraryW,LPCWSTR: MSFTEDIT.DLL'}
{'type': 'send', 'payload': 'LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE'}
--------------------------------------------------
        [+] Potential DllMain Sideloading: LoadLibraryW,LPCWSTR: MSFTEDIT.DLL
        [+] Potential DllMain Sideloading: LoadLibraryExW,LPCWSTR : MSFTEDIT.DLL, dwFlags : NONE
Baixar ferramenta