Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
工具/GitHubGitHub/blacksnufkin/axhunter
Privilege EscalationPassword AttacksVulnerability AnalysisExploitationPost-ExploitationBinary Exploitation
GitHubblacksnufkin/axhunter

AxHunter

PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430, CVE-2026-3609).

查看仓库
12123天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

AxHunter

PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family — xhunter1.sys v2023.12.7.78 (CVE-2026-3609) and xhunter2.sys v2026.6.1.192 (CVE-2026-15430).

Workspace layout

Cargo workspace, three crates:

root@kitploit:~
AxHunter/
├── Cargo.toml               workspace manifest
├── axhunter-lsa/            shared crate — driver-agnostic LSA extraction (MemReader trait,
│                              LDR walk, BCrypt 3DES key extraction, LogonSessionList,
│                              WDigest). Consumed by both PoCs.
├── axhunter_v1/             xhunter1.sys v2023.12.7.78  (CVE-2026-3609)
└── axhunter_v2/             xhunter2.sys v2026.6.1.192  (CVE-2026-15430)

Each PoC crate carries its own target driver binary (xhunter1.sys, xhunter2.sys) and — in axhunter_v2/src/ — Wellbia's WBMF module (wbmf_module.dll) extracted from a live WindSlayer.exe process.

Build

From the workspace root:

root@kitploit:~
cargo build --release              # builds both binaries + shared crate
cargo build --release -p AxHunter_v1
cargo build --release -p AxHunter_v2

Both binaries land in target/release/:

root@kitploit:~
target/release/AxHunter_v1.exe
target/release/AxHunter_v2.exe

Unified CLI

Both binaries share the same flags:

root@kitploit:~
AxHunter_v1.exe -m {dump|kill|lpe|inject|all} [-t <pid|image>] [-d <device>] [-p <payload.bin>]
AxHunter_v2.exe -m {dump|kill|lpe|inject|all} [-t <pid|image>] [-d <device>] [-p <payload.bin>]

See each crate's README for driver-specific defaults and mode details.

Companion write-ups

  • Hunting the Hunter — xhunter1.sys v2023.12.7.78. Corresponds to axhunter_v1/.
  • Hunting the Hunter II — xhunter2.sys v2026.6.1.192. Corresponds to axhunter_v2/.

Comparison

Sibling reference

  • CVE-2026-3609 — xhunter1.sys v10.0.10011.16384 through v2023.12.7.78 (write-up, legacy PoC at CredsHunter).

License

MIT. See LICENSE.

下载工具
Propertyxhunter1.sys v2023.12.7.78xhunter2.sys v2026.6.1.192
CVECVE-2026-3609CVE-2026-15430
TransportIRP_MJ_WRITE, 624-byte plaintext frameIRP_MJ_WRITE, 1184-byte LCG-XOR-encrypted frame
Frame magic0x345821AB0x70506202 (MAGIC ^ SEED_KEY)
Device open authNoneWBMF RSA-2048 signed PE + Win32StartAddress in-PE
Per-request authNoneWBCC blob + certificate chain iterator
PID gate escalationcmd 777 + cmd 775cmd 777 + cmd 779 + cmd 775
cmd 785 (PPL handle mint)ObOpenObjectByPointer(KernelMode)identical
cmd 787 (cross-process read)KeStackAttachProcess byte copyidentical
cmd 800 (handle stomp kill)KeStackAttachProcess + ObSetHandleAttributes(KernelMode) + ZwCloseidentical
cmd 820 (kernel injection)RWX alloc + copy + RtlCreateUserThread (all ring 0)identical