ccelikanil / DFMI
PublicAnother FAFO project: Weaponizing MSI installers for fileless code execution
A suite of tools for modifying Windows installer files to execute custom payloads during installation for authorized red teaming and security research.
How It Works
You stumble upon this security testing tool on a code sharing site while looking for ways to check installer safety.
You download the program and run it on your Windows or Linux computer with a few simple preparations.
Hide your test action inside a real software setup file.
Create a small extra file that works with a signed setup without changing it.
Make a standalone setup that looks like a normal software update.
Point it to your practice server or script so it knows what secret action to perform during the test.
With one command, it creates a modified setup file that runs your test perfectly while looking innocent.
Double-click or launch the installer on a test machine, watching it install normally.
Your hidden test action fires silently with no files left behind, helping you spot security gaps.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.