Skip to content

Tool to bypass LSA Protection (aka Protected Process Light)

Notifications You must be signed in to change notification settings

asdlei99/PPLKiller

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 
 
 
 
 

Repository files navigation

PPLKiller

Tool to bypass LSA Protection (aka Protected Process Light)

I’ve noticed there is a common misconception that LSA Protection prevents attacks that leverage SeDebug or Administrative privileges to extract credential material from memory, like Mimikatz. LSA Protection does NOT protect from these attacks, at best it makes them slightly more difficult as an extra step needs to be performed.

The driver file can be downlaoded here: http://download-eu2.guru3d.com/afterburner/[Guru3D.com]-MSIAfterburnerSetup462Beta2.zip You just need to extract RTCore64.sys from the installer using something like 7zip and place into in the same folder as the PPLKiller executable.

Usage and Demo

Bypassing LSA Protection

About

Tool to bypass LSA Protection (aka Protected Process Light)

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • C++ 100.0%