PPL & LSASS Security Analysis
Budget: $30 – $250 USD
My Windows machine is behaving oddly and recent checks revealed that both the Protected Process Light (PPL) components and the LSASS executable appear corrupted. I attempted a manual repair, but the integrity issues persist, so I now need a focused security analysis.
The job centers on three objectives:
1. Verify whether the current PPL-protected binaries and LSASS file are genuinely corrupted or maliciously altered.
2. Trace the source or vector that introduced the corruption and document any privilege-escalation activity.
3. Deliver a clear remediation plan—including clean replacement files, hardening steps, and a concise report of findings with evidence (hashes, event-log excerpts, or memory dump analysis).
Any method that respects system stability is fine, but familiarity with WinDbg, Sysinternals tools, offline disk imaging, and memory-forensics frameworks such as Volatility will speed things up. The end result should leave me with a verified clean LSASS, restored PPL integrity, and documented steps to prevent a repeat incident.
The job centers on three objectives:
1. Verify whether the current PPL-protected binaries and LSASS file are genuinely corrupted or maliciously altered.
2. Trace the source or vector that introduced the corruption and document any privilege-escalation activity.
3. Deliver a clear remediation plan—including clean replacement files, hardening steps, and a concise report of findings with evidence (hashes, event-log excerpts, or memory dump analysis).
Any method that respects system stability is fine, but familiarity with WinDbg, Sysinternals tools, offline disk imaging, and memory-forensics frameworks such as Volatility will speed things up. The end result should leave me with a verified clean LSASS, restored PPL integrity, and documented steps to prevent a repeat incident.