{"repo":"ghostvectoracademy/DLLHijackHunter","free":true,"listed":false,"github":"https://github.com/ghostvectoracademy/DLLHijackHunter","clone":"git clone https://github.com/ghostvectoracademy/DLLHijackHunter.git","description":"Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.","language":"C#","stars":396,"topics":["bug-bounty","bugbounty","bugbounty-tool","cybersecurity","cybersecurity-tools","dll-hijacking","dll-hooking","dll-injection","red-team","red-team-tools"],"license":"MIT","category":"security-tools","readme_excerpt":"DLLHijackHunter By GhostVector Academy Automated DLL Hijacking Discovery, Validation, and Confirmation Turning local misconfigurations into weaponized, confirmed attack paths. --- Overview DLLHijackHunter is an automated Windows DLL hijacking detection tool that goes beyond static analysis. It discovers, validates, and confirms DLL hijacking opportunities using a multi-phase pipeline: 1. Discovery — Enumerates binaries across services, scheduled tasks, startup items, COM objects, and AutoElevate UAC bypass vectors 2. Filtration — Eliminates false positives through intelligent hard and soft gates 3. Canary Confirmation — Deploys a harmless canary DLL and triggers the binary to prove the hijack works 4. Scoring & Reporting — Ranks findings by exploitability with a tiered confidence system Most DLL hijacking tools stop at “this DLL might be hijackable.” DLLHijackHunter attempts to validate it, cross-reference it against known exploit intelligence, and confirm real execution paths where possible. --- Architecture --- Key Features Hijack Type Coverage Type Description Stealth Status --- --- --- --- Phantom DLL doesn't exist anywhere on disk High Implemented Search Order Place DLL earlier in the Windows search order High Implemented Side-Loading Abuse legitimate app loading DLLs from its directory High Implemented (AutoElevate copy-to-temp path) .local Redirect Hijack via .local directory redirection High Implemented ENV PATH Weaponization of writable directories in system PATH Hig","default_branch":null,"files":null,"tree":[],"storefront":"/r/ghostvectoracademy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ghostvectoracademy/DLLHijackHunter/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}