Skip to content

jsacco/PPL_Bypass

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

PPL_Bypass - Proof of concept

How to run: \WritePPLMem.exe -d -v -f MsMpEng.exe 1

Credits: To all the work and research done by James Forshaw from Project Zero: https://googleprojectzero.blogspot.com/2018/08/windows-exploitation-tricks-exploiting.html

For the DLL Phantom Hollowing technique from Forrest Orr https://www.forrest-orr.net/post/malicious-memory-artifacts-part-i-dll-hollowing

For the amazing work on Syscall Whispers Jackson T. https://github.com/jthuraisamy/SysWhispers

For making publicly available an implementation of NT/System token impersonation, thanks! FULLSHADE https://github.com/FULLSHADE/Auto-Elevate

For an incredible implementation and the PPLDump PoC itm4n ! https://github.com/itm4n/PPLdump

To all those anonymous people from StackOverflow questions/answers! and Microsoft for not fixing this !

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages