Skip to content

v2.0.0: Attack Chain Discovery

Choose a tag to compare

@projectmerai projectmerai released this 09 Mar 06:46
· 41 commits to main since this release

🚀 What's New

Attack Chain Correlation

We've introduced a new correlation engine that analyzes isolated findings and stitches them together into realistic, actionable exploit paths. Instead of just seeing 50 vulnerable DLLs, you now see exactly how an attacker would use them to take over the machine.

The engine currently detects three distinct exploit chains:

  • The Direct Path (User → SYSTEM)

  • Identifies critical misconfigurations where a standard user can directly hijack a SYSTEM-level process (e.g., via a globally writable PATH directory or a vulnerable CWD load).

  • The Ladder (User → Admin → SYSTEM)

  • Models a realistic Red Team escalation path. It correlates a silent UAC Bypass vulnerability with a high-privilege payload. The engine is smart enough to ensure that the chosen SYSTEM payload actually requires the UAC bypass to exploit (e.g., writing to C:\Program Files).
    The Long Con (User → Persistence)

  • Identifies findings that survive a reboot (e.g., Run keys, Startup folder items) and links them to an initial foothold, demonstrating how an attacker would maintain stealthy access without triggering alarms.

Minor Fixes & Polish

Updated all internal reporting and console banners to reflect the v2.0.0 release.
Refined the WritabilityFilter integration to ensure Attack Chains only use targets that are guaranteed to be writable by the current user.