Offensive-security research
The still point in
offensive security.
ProjectMerai is an offensive-security outfit. We take apart the systems people rely on and understand them to the bottom. Rigorous, exacting, and open by default.
Flagship tool
DLLHijackHunter
Automated discovery, validation, and confirmation of DLL hijacking paths on Windows. Validation-driven by design: its verdict is confirmed, not suspected.
- language
- C# / .NET 8.0
- license
- MIT
- stars
- 401 ★
Canary confirmation
Plants a harmless test DLL and proves it loads, eliminating the false positives that Robber, DLLSpy and WinPEAS leave you to triage by hand.
Multi-phase pipeline
Discovery → Filtration → Canary Confirmation → Scoring. Confirmation is the gate: nothing is reported until it is proven exploitable.
Five scan profiles
Aggressive, Strict, Safe, Redteam and UAC-bypass, spanning read-only recon through operational realism across an integrity boundary.
Reports that travel
Console, JSON and HTML output, ready to drop straight into an assessment or a CI pipeline.
Research
The work, written down
Long-form vulnerability research, methodology, and tool internals. Written to be read.