INNER CODE UNIT · C#
GetForwardModuleBase
ghostvectoracademy/DLLHijackHunter · src/DLLHijackHunter/Canary/CanaryDllBuilder.cs:133
public static string GetForwardModuleBase(string deployPath) =>
// PE forwarder strings are split at the FIRST dot by the Windows loader.
// Using ".hhorig" produces "foo.hhorig.Export" which the loader misparses as
// module="foo" (the canary itself) with export="hhorig.Export" — not found,
// so the import snap fails before DllMain runs. Using "_hhorig" (underscore)
// produces "foo_hhorig.Export" — one dot, unambiguous, resolves to sidecar.
Path.GetFileNameWithoutExtension(deployPath) + "_hhorig";
/// <summary>
/// The sidecar path (the runtime proxy's forward target) for a canary deployed to
/// <paramref name="deployPath"/>: a copy of the original DLL under a distinct name in the
/// same directory, so forwarders point at real code rather than at the canary itself.
/// </summary>
public static string GetSidecarPath(string deployPath)
{
string dir = Path.GetDirectoryName(deployPath) ?? "";
return Path.Combine(dir, GetForwardModuleBase(deployPath) + ".dll");
}