⤷ Title: ComDotNetExploit: PoC for Windows PPL Bypass via COM-to-.NET
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 25 May 2025 01:30:03 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #.NET #code injection #COM #cybersecurity #exploit #LSASS #PPL #reflection #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 25 May 2025 01:30:03 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #.NET #code injection #COM #cybersecurity #exploit #LSASS #PPL #reflection #Windows Security
Penetration Testing Tools
ComDotNetExploit: PoC for Windows PPL Bypass via COM-to-.NET
ComDotNetExploit is a C++ PoC demonstrating PPL bypass in Windows using COM-to-.NET redirection and reflection for code injection.
⤷ Title: Dragon Breath APT Deploys RoningLoader, Using Kernel Driver and PPL Abuse to Disable Windows Defender
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:05:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Defense Bypass #Dragon Breath #Gh0st RAT #Kernel Driver #PPL Abuse #Protected Process Light #RoningLoader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:05:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Defense Bypass #Dragon Breath #Gh0st RAT #Kernel Driver #PPL Abuse #Protected Process Light #RoningLoader
Daily CyberSecurity
Dragon Breath APT Deploys RoningLoader, Using Kernel Driver and PPL Abuse to Disable Windows Defender
Elastic exposed Dragon Breath APT's new RoningLoader malware. It uses PPL abuse and a signed kernel driver (ollama.sys) to disable Windows Defender and inject a modified gh0st RAT for espionage.
⤷ Title: Beyond the Memory: How LSA Whisperer BOF Bypasses PPL and Credential Guard Without Touching LSASS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:04:12 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BOF #Cloud SSO #Cobalt Strike #Credential Guard #DPAPI #Kerberos #LSA Whisperer #LsaCallAuthenticationPackage #LSASS #Pentesting #PPL #red teaming #SpecterOps #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:04:12 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BOF #Cloud SSO #Cobalt Strike #Credential Guard #DPAPI #Kerberos #LSA Whisperer #LsaCallAuthenticationPackage #LSASS #Pentesting #PPL #red teaming #SpecterOps #Windows Security
Penetration Testing Tools
Beyond the Memory: How LSA Whisperer BOF Bypasses PPL and Credential Guard Without Touching LSASS
Interact with Kerberos and DPAPI without opening an LSASS handle. LSA Whisperer BOF uses official APIs to bypass PPL and Credential Guard during red teaming.