TwoSevenOneT/CreateProcessAsPPL
This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.
Tool to bypass LSA Protection (aka Protected Process Light)
Appears on
Quick read
Latest capture 2026-09-02 03:06
0 paths
Agent instructions and tool configuration found in this repository.
No config files detected.
4 observed captures since 2026-06-24. Observed captures are shown by default.
Stars from first capture 0
Observed captures only
All tracked data
Observed snapshots
Observed snapshots
Nearest indexed repositories by embedding similarity.
This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.
KslDump — Why bring your own knife when Defender already left one in the kitchen?
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
PoC exploit for the vulnerable WatchDog Anti-Malware driver (amsdk.sys) – weaponized to kill protected EDR/AV processes via BYOVD.
Proof of Concepts code for Bring Your Own Vulnerable Driver techniques
This bypass is for anti cheats like battleye and EAC. All this does is abuse lsass's handles and use them for yourself. This is quite useful as this is usermode which doesnt require you to find a way to load a driver