MCPcopy Create free account
hub / github.com/Slowerzs/PPLSystem

github.com/Slowerzs/PPLSystem @main

Chat with this repo
repository ↗ · DeepWiki ↗ · + Follow
138 symbols 246 edges 15 files ⚖ MIT 8 documented · 6% updated 2y ago★ 211

Browse by type

Functions 70 Types & classes 68
What it actually does AI analysis from the code graph — generated when you open this
loading…
README

PPLSystem

This is a proof of concept implementation of the technique described in this blog post.

It creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.

The livedump might slow down or freeze the machine for a couple of seconds.

The tool can be built using: cargo build --release.

Usage

pplsystem.exe --dll <path to the unsigned DLL to load> --dump <Full path where the dump file will be written> --pid <PID of the process to inject>

Image of the exploitation

This proof of concept implements the mapping of an unsigned DLL inside a PPL process, however, no new thread is created, and the code in the unsigned DLL is not called.

For some reason, in a virtual machine, I've found that services.exe does not always initialize COM. In such cases, injection does not work. It works on other PPL process who do initialize COM.

I haven't faced this issue on a physical machine.

Credits

Extension points exported contracts — how you extend this code

browse all types & interfaces →

Core symbols most depended-on inside this repo

browse all functions →

Shape

Class 53
Function 43
Method 27
Interface 10
Enum 5

Languages

Rust100%

Modules by API surface

src/irundown/structs.rs33 symbols
src/kdmp/parser.rs31 symbols
endian_codec/src/lib.rs29 symbols
endian_codec/endian_codec_derive/src/lib.rs14 symbols
src/irundown/inject.rs10 symbols
src/kdmp/structs.rs6 symbols
src/irundown/locate.rs5 symbols
src/irundown/rpcss.rs4 symbols
src/dmp/dumper.rs3 symbols
src/main.rs2 symbols
endian_codec/endian_codec_derive/src/attr.rs1 symbols

For agents

$ claude mcp add PPLSystem \
  -- python -m otcore.mcp_server <graph>

⬇ download graph artifact

Ask about this repo answers extend the page