How to run: \WritePPLMem.exe -d -v -f MsMpEng.exe 1
Credits: To all the work and research done by James Forshaw from Project Zero: https://googleprojectzero.blogspot.com/2018/08/windows-exploitation-tricks-exploiting.html
For the DLL Phantom Hollowing technique from Forrest Orr https://www.forrest-orr.net/post/malicious-memory-artifacts-part-i-dll-hollowing
For the amazing work on Syscall Whispers Jackson T. https://github.com/jthuraisamy/SysWhispers
For making publicly available an implementation of NT/System token impersonation, thanks! FULLSHADE https://github.com/FULLSHADE/Auto-Elevate
For an incredible implementation and the PPLDump PoC itm4n ! https://github.com/itm4n/PPLdump
To all those anonymous people from StackOverflow questions/answers! and Microsoft for not fixing this !