March 9, 2026 at 02:03AM

■■■□□ DLLHijackHunter is an automated Windows DLL hijacking detection tool that goes beyond static analysis. It discovers, validates, and confirms DLL hijacking opportunities using a multi-phase pipeline:

Discovery — Enumerates binaries across services, scheduled tasks, startup items, COM objects, and AutoElevate UAC bypass vectors
Filtration — Eliminates false positives through 8 intelligent gates (hard gates + confidence-adjusting soft gates)
Canary Confirmation — Deploys a harmless canary DLL and triggers the binary to prove the hijack works
Scoring & Reporting — Ranks findings by exploitability with a tiered confidence system.

https://github.com/ghostvectoracademy/DLLHijackHunter