Dumping lsass | Bypassing LSA Protection - PPLFault | Windows 11

Опубликовано: 16 Декабрь 2023
на канале: Exploit Blizzard
593
12

💬
The PPL mechanism was introduced in Windows 8.1, enabling specially-signed programs to run in such a way that they are protected from tampering and termination, even by administrative processes.

👀
On September 1, 2023, Microsoft released build 25941 of Windows Insider Canary. This build adds a new check to the memory manager function

admin-to-PPL : github.com/gabriellandau/PPLFault

====
🔗 Join Discord : discord.gg/2dhSGeN6Nz

🔗 Follow On Github : github.com/exploitblizzard