Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Filefix Hunter

Rust License: MIT Build

FileFix Hunter Logo

Filefix-Hunter is a forensic tool written in Rust for incident response. It enumerates TypedPaths entries in Windows registry to detect possible LOLBIN or FileFix exploitation traces.


🚀 Purpose

  • Scan all HKEY_USERS\<SID>\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths for each user.
  • Look for suspicious commands, LOLBINs, known IOCs (Mimikatz, shellcode).
  • Highlight suspicious entries (red) vs safe entries (yellow).
  • Optionally export results to JSON or CSV.

⚠️ filefix Vulnerability

The filefix attack exploits careless user behavior by getting them to paste malicious commands into Explorer’s address bar, leading to code execution with LOLBINs. More info here.


🔧 Setup Environment for Windows cross-compilation

If building on Linux to produce a Windows binary:

sudo apt update
sudo apt install -y build-essential pkg-config libssl-dev rustup gcc-mingw-w64

rustup default stable
rustup target add x86_64-pc-windows-gnu
source $HOME/.cargo/env

🛠️ Build

Clone the repository and build the Windows binary:

git clone https://github.com/FreeDurok/Filefix-Hunter.git
cd filefix-hunter
cargo build --release --target x86_64-pc-windows-gnu

🚀 Usage

filefix-hunter [options]

Options:

  • -h, --help : show help
  • -f, --format <json|csv|none> : export format
  • -o, --output <file> : output file name

Examples:

filefix-hunter -f json -o report.json
filefix-hunter --format=csv --output=report.csv

📝 Output

Example Output

Records highlighted in red are those that match suspicious entries detected by the tool.

Filefix Hunter Usage Example

JSON/CSV includes:

  • sid, username, name, value
  • suspicious: true/false
  • matched reason

📝 License

MIT License


About

filefix-hunter is a Rust tool for DFIR on Windows. It scans TypedPaths to detect suspicious commands, LOLBIN traces, or filefix exploits. Outputs results to console, JSON, or CSV.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages