Category: Post Exploitation

PPLdump

PPLdump: dumping the memory of any PPL

PPLdump This tool implements a userland exploit that was initially discussed by James Forshaw (a.k.a. @tiraniddo) – in this blog post – for dumping the memory of any PPL as an administrator. I wrote two blog posts...

ARTi-C2

ARTi-C2: post-exploitation framework

ARTi-C2 ARTi-C2 is a modern execution framework built to empower security teams to scale attack scenario execution from single and multi-breach point targets with the intent to produce actionable attack...

HookDump: EDR function hook dumping

HookDump EDR function hook dumping. Hook Types Detected JMP A jump instruction has been patched into the function to redirect execution flow WOW Detection of the WOW64 syscall stub being...