Loading video...

Video Failed to Load

Go Home

Did some experiments on bypassing PPL Protection and Windows Defender, to dump LSASS. No detections so far! tasty pepperoni's PPLBlade repo: My short write-up: #adversarytactics #redteam #tacticaladversary #PPLBlade

3 Comments

Abhijith B R's profile picture
Abhijith B R3 years ago

PPLBlade Could be used to simulate adversarial actions against endpoint defense measures in Windows systems.

Sam ☁️🪵's profile picture
Sam ☁️🪵3 years ago

@tastypepperoni Again, nice @abhijithbr ! In terms of prevention I don't see much except priv esc controls before getting admin. Detection wise, driver/image loaded? Do you see anything else?

Joe's profile picture
Joe3 years ago

@rsnksg @tastypepperoni

Related Videos