Skip to content

Latest commit

 

History

History
17 lines (11 loc) · 1.35 KB

File metadata and controls

17 lines (11 loc) · 1.35 KB

PPLrevenant

poc.webm

This is a proof-of-concept that shows how a technique such as Bring Your Own Vulnerable DLL (BYODLL) could be used to bypass LSA Protection, or more generally execute arbitrary code within Protected Processes on Windows.

For more information, please check out my blog post series entitled "Ghost in the PPL".

Credits