KslDump — Why bring your own knife when Defender already left one in the kitchen?
-
Updated
Mar 17, 2026 - Python
KslDump — Why bring your own knife when Defender already left one in the kitchen?
Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass
🥶 Freeze EDR/AV processes with ColdWer, using WerFaultSecure.exe PPL bypass to extract LSASS memory on modern Windows systems.
Add a description, image, and links to the ppl-bypass topic page so that developers can more easily learn about it.
To associate your repository with the ppl-bypass topic, visit your repo's landing page and select "manage topics."