Skip to content

Releases: shellkraft/Anvil

Anvil-v1.0.0-x64

16 Mar 08:09
0262240

Choose a tag to compare

Initial Release

Modules

DLL Hijacking · COM Hijacking · Binary Hijacking · Symlink Attacks · Insecure Configuration Files · Insecure Installation Directory · Named Pipe ACL · Registry Privilege Escalation · Unquoted Service Path · PE Security Mitigations · Sensitive Strings in Memory

Requirements

  • Windows 10/11 or Windows Server 2016+
  • Must be run as Administrator

Enterprise EDRs might block this binary at runtime due to its use of token duplication and ReadProcessMemory. Add an exclusion for Anvil.exe in your EDR/AV before running, or execute from a dedicated non-managed assessment VM.

Windows SmartScreen may also block on first run as the binary is unsigned.