Skip to content

A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and reflection techniques for code injection. This PoC showcases bypassing code integrity checks and loading malicious payloads in highly protected processes such as LSASS. Based on research from James Forshaw.

active 2025-03-02 → 2026-01-23 (UTC)

Complete coverage27,320 / 27,320 hourly files (100%) · 2 absent upstream2023-08-15 → 2026-09-26 (UTC)
Events
336
Pushes
8
Pull requests
1
Issues
2
Stars
279
Forks
39

Activity over time

Daily event counts in the loaded window

Line chart, 328 days from 2025-03-02 to 2026-01-23. Pushes: 8 total, peak 6 in a day. Pull requests: 1 total, peak 1 in a day. Issues: 2 total, peak 2 in a day. Comments: 5 total, peak 5 in a day. Stars: 279 total, peak 77 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

ContributorContributionsPushesPRsComments
T3nb3w11811
cookpoo784003
breachlabs-org1001

Recent activity

Latest issues, pull requests and releases

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 279 stars here means stars gained during the window, not the repo's star count.