Releases: shellkraft/Anvil
Releases · shellkraft/Anvil
Anvil-v1.0.0-x64
Initial Release
Modules
DLL Hijacking · COM Hijacking · Binary Hijacking · Symlink Attacks · Insecure Configuration Files · Insecure Installation Directory · Named Pipe ACL · Registry Privilege Escalation · Unquoted Service Path · PE Security Mitigations · Sensitive Strings in Memory
Requirements
- Windows 10/11 or Windows Server 2016+
- Must be run as Administrator
Enterprise EDRs might block this binary at runtime due to its use of token duplication and
ReadProcessMemory. Add an exclusion forAnvil.exein your EDR/AV before running, or execute from a dedicated non-managed assessment VM.
Windows SmartScreen may also block on first run as the binary is unsigned.