ServiceMove-BOF

DLL Hijacker

A tool that exploits a Windows vulnerability to execute arbitrary code on remote systems using a technique called DLL hijacking.

New lateral movement technique by abusing Windows Perception Simulation Service to achieve DLL hijacking code execution.

GitHub

284 stars
6 watching
46 forks
Language: C
last commit: over 4 years ago

Related projects:

RepositoryDescriptionStars
octoberfest7/dropspawn_bofA CobaltStrike payload that uses DLL hijacking to spawn additional Beacons on Windows systems219
netero1010/rdphijack-bofA tool for hijacking remote RDP sessions using the WinStationConnect API297
espressocake/dll-hijack-search-order-bofA tool to enumerate the search order of DLL resolution and potentially gain information about a file's mutability.141
tomcarver16/bof-dll-injectA tool for injecting malware into processes by mapping it to memory without registering it with the kernel.147
mojtabatajik/robberTools to detect DLL hijacking vulnerabilities in executable files767
filosottile/otherportA tool to redirect network connections to alternative ports.42
octoberfest7/killdefender_bofA tool that allows an attacker to elevate privileges and gain control over the Windows Defender service62
rsmudge/zerologon-bofAn implementation of a Zero Logon protocol Bounce Of Flood (ZoBoF) vulnerability exploitation technique157
ideaslocas/adllA tool for detecting DLL hijacking vulnerabilities in binaries.70
espressocake/firewall_walker_bofAn exploit technique allowing interaction with Windows software firewall via COM interfaces.100
xforceir/sideloadhunterA tool to help identify DLL sideloading on Windows systems.23
trustedsec/cs-remote-ops-bofProvides tools and primitives for interacting with Microsoft Windows systems remotely.892
nul0x4c/atomldrA DLL loader with advanced evasion techniques to bypass user-land hooks and load malicious payloads.676
octoberfest7/cve-2023-36874_bofAn exploit tool for a Windows vulnerability allowing an attacker to run arbitrary code as SYSTEM on Windows 10 and Windows 11202