Repository navigation
v2.1.0 - LPE Only Addition
Now you have the best of both worlds.
When you want to find Guaranteed 0-Day Standard User -> SYSTEM Exploits, you open an Administrator PowerShell window and run this exact command:
.\DLLHijackHunter.exe --profile aggressive --lpe-only
What this does:
- --lpe-only strips away all the "boring" Admin-to-SYSTEM persistence bugs in System32 and Program Files. It forces the tool to only look at ProgramData, %PATH%, and other messy user-writable folders.
- Administrator Rights gives the tool the power to instantly restart the services (net stop / start) without you having to reboot the computer.
- --profile aggressive unleashes the Canary DLL to prove that Windows mitigations won't block the exploit.