Elastic Security Labs reverse engineered Microsoft Time Travel Debugging (TTD), a Windows execution-recording framework that logs user-mode instructions and process state to .run trace files for replay in WinDbg. Its analysis mapped the roles of ttdrecord.dll, TTDInject.exe, TTDRecordCPU.dll, undocumented Windows instrumentation callbacks, and the ProcLaunchMon.sys driver in injecting and recording target processes.
Researchers found that TTD can trace processes without activating conventional anti-debugging checks and that its signed CreateDump.exe component can be used to dump process memory. A concealed PplDebuggingToken option can permit access to Protected Process Light targets, including LSASS, but requires a valid Microsoft-signed, device-bound supplemental Code Integrity policy and is therefore not a practical general-purpose PPL bypass. Defenders can monitor or block TTD components and associated trace activity to reduce abuse risk.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs reverse engineered Microsoft Time Travel Debugging components and documented its tracing architecture, hidden PplDebuggingToken option, potential process-dumping implications, and detection and mitigation approaches. The analysis found that PPL access using the token requires a valid Microsoft-signed, device-bound Code Integrity policy, limiting its practicality as a general PPL bypass.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.