
criPPLe
Windows kernel driver that removes Process Protection (PP) and Process Protection Light (PPL).

Windows kernel driver that removes Process Protection (PP) and Process Protection Light (PPL).

Proof-of-concept C exploit that runs a DLL with WinTcb-Light protection from userland, demonstrating a Windows privilege-escalation primitive and…

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.

Poc for CVE-2025-7771 to modify PPL Protection

WordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin <= 2.4.37 is vulnerable to Privilege Escalation

Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)

Gives you one-liners that aids in penetration testing operations, privilege escalation and more

Windows privilege escalation exploit abusing a TOCTOU in Code Integrity to bypass Protected Process Light, execute as WinTcb-Light, and dump…