DumpThatLSASS Save Abandoned

Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation , it contains Anti-sandbox , if you run it under unperformant Virtual Machine you need to uncomment the code related to it and recompile.

Project README

DumpThatLSASS

It's Fully Undetectable and bypass almost all the vendors AV/EDRs, it doesn't bypass RunAsPPL

Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation, duplicate lsass handle from existed processes.

The execution may take time, bcz of sandboxing check

MiniLSASS

DumpThatLsass

Open Source Agenda is not affiliated with "DumpThatLSASS" Project. README Source: D1rkMtr/DumpThatLSASS
Stars
480
Open Issues
0
Last Commit
1 year ago

Open Source Agenda Badge

Open Source Agenda Rating