timwhitez starred DumpThatLSASS
2022-9-27 21:11:5 Author: github.com(查看原文) 阅读量:39 收藏

It's Fully Undetectable and bypass almost all the vendors AV/EDRs, it doesn't bypass RunAsPPL

Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation, duplicate lsass handle from existed processes.

The execution may take time, bcz of sandboxing check

it contains Anti-sandbox , if you run it under unperformant Virtual Machine you need to uncomment the code related to Anti-Debuging and Anti-Sandboxing at the beginning of the main and recompile.

MiniLSASS

DumpThatLsass


文章来源: https://github.com/D1rkMtr/DumpThatLSASS
如有侵权请联系:admin#unsafe.sh