Skip to content

v2.1.0 - LPE Only Addition

Choose a tag to compare

@projectmerai projectmerai released this 10 Mar 09:53
· 41 commits to main since this release

Now you have the best of both worlds.

When you want to find Guaranteed 0-Day Standard User -> SYSTEM Exploits, you open an Administrator PowerShell window and run this exact command:

.\DLLHijackHunter.exe --profile aggressive --lpe-only

What this does:

  • --lpe-only strips away all the "boring" Admin-to-SYSTEM persistence bugs in System32 and Program Files. It forces the tool to only look at ProgramData, %PATH%, and other messy user-writable folders.
  • Administrator Rights gives the tool the power to instantly restart the services (net stop / start) without you having to reboot the computer.
  • --profile aggressive unleashes the Canary DLL to prove that Windows mitigations won't block the exploit.