Offensive-security research
The still point in
offensive security.
ProjectMerai is an offensive-security outfit. We take apart the systems people rely on and understand them to the bottom. Rigorous, exacting, and open by default.
Flagship tool
DLLHijackHunter
black hat®· Arsenal ’26Automated discovery, validation, and confirmation of DLL hijacking paths on Windows. Validation-driven by design: its verdict is confirmed, not suspected.
- language
- C# / .NET 8.0
- license
- MIT
- stars
- — ★
Canary confirmation
Plants a harmless test DLL and proves it loads, eliminating the false positives that Robber, DLLSpy and WinPEAS leave you to triage by hand.
Multi-phase pipeline
Discovery → Filtration → Canary Confirmation → Scoring. Confirmation is the gate: nothing is reported until it is proven exploitable.
Five scan profiles
Aggressive, Strict, Safe, Redteam and UAC-bypass, spanning read-only recon through operational realism across an integrity boundary.
Reports that travel
Console, JSON and HTML output, ready to drop straight into an assessment or a CI pipeline.
Research
The work, written down
Long-form vulnerability research, methodology, and tool internals. Written to be read.