Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

PPLdump Is Dead - Long Live PPLdump

Black Hat via YouTube

Overview

Coursera Plus Annual Sale: All Certificates & Courses 25% Off!
Explore the intricacies of Windows Protected Process Light (PPL) mechanism and its vulnerabilities in this 30-minute Black Hat conference talk. Delve into the history of PPL bypasses, focusing on the notorious PPLdump tool and its implications for Windows security. Learn about the design of PPL, its role in hardening anti-malware and critical Windows services, and the Windows Code Integrity subsystem. Examine the long-lived vulnerabilities in PPL, their real-world impact, and Microsoft's approach to patching these issues. Gain insights into historical exploits, their mitigations, and the ongoing challenges in securing Windows systems against PPL bypasses.

Syllabus

PPLdump Is Dead. Long Live PPLdump!

Taught by

Black Hat

Reviews

Start your review of PPLdump Is Dead - Long Live PPLdump

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.