github Actively maintained

gmh5225/PPLKiller

Tool to bypass LSA Protection (aka Protected Process Light)

1 awesome list

Quick read

Stars
0
Forks
0
Open issues
0
Commits
23

Activity and growth

Latest capture 2026-07-30 03:03

Stars · last 7 days
No history
Commits · last 7 days
No history
Stars since tracking
0
Stored snapshots
3

Metadata

Default branch
master
Created
2022-09-24
First commit
2020-07-06
Last pushed
2022-02-11
GitHub updated
2022-09-24
Last synced
2026-07-30 03:03
Stack scanned
2026-07-30 03:03
Archived
No

AI development signals

0 paths

Agent instructions and tool configuration found in this repository.

No config files detected.

Growth history

Tracked growth

3 observed captures since 2026-06-24. Charts use measured snapshots only.

Stars from first capture 0

Time horizon

All tracked data

Custom date range

Stars history

Observed snapshots

Commits history

Observed snapshots

Similar repositories

Nearest indexed repositories by embedding similarity.

TwoSevenOneT/CreateProcessAsPPL

This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.

302 stars
C++ 1 awesome list

andreisss/KslDump

KslDump — Why bring your own knife when Defender already left one in the kitchen?

396 stars
Python 1 awesome list

gmh5225/WatchDogKiller

PoC exploit for the vulnerable WatchDog Anti-Malware driver (amsdk.sys) – weaponized to kill protected EDR/AV processes via BYOVD.

0 stars
1 awesome list

0xJs/BYOVD_EDRKiller

Proof of Concepts code for Bring Your Own Vulnerable Driver techniques

115 stars
C 1 awesome list

ContionMig/LSASS-Usermode-Bypass

This bypass is for anti cheats like battleye and EAC. All this does is abuse lsass's handles and use them for yourself. This is quite useful as this is usermode which doesnt require you to find a way to load a driver

103 stars
C++ 1 awesome list