Home / Companies / Elastic / Blog / Post Details
Content Deep Dive

Protecting Windows protected processes

Blog post from Elastic

Post Details
Company
Date Published
Author
Gabriel Landau
Word Count
731
Company Posts That Month
25
Language
-
Hacker News Points
-
Post removed?
No
Summary

Gabriel Landau's blog post discusses a Windows exploit that allows attackers to perform highly privileged actions typically requiring a kernel driver by exploiting a vulnerability in the DefineDosDevice API to tamper with the KnownDlls cache. This exploit, affecting Windows 10 version 21H1, enables attackers to inject a DLL into a Protected Process Light (PPL) process, thereby performing actions with WinTcb privileges, such as dumping enterprise credentials and disabling security products. The blog highlights the release of PPLDump, an open-source tool showcasing this exploit, and its subsequent adaptation into Sealighter-TI, which accesses restricted Threat-Intelligence feeds. To address the vulnerability, the blog introduces PPLGuard, a tool that hardens the KnownDlls object directory by applying a dynamic access control list (DACL) to block the exploit. The post emphasizes the potential for offensive tools to exploit this vulnerability and hints at a future discussion on using Elastic Security to detect such attacks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.