Dumping Lsass Without Mimikatz
PreviousDumping Credentials from Lsass Process Memory with MimikatzNextDumping Lsass without Mimikatz with MiniDumpWriteDump
Last updated
Was this helpful?
Last updated
Was this helpful?
See my notes about writing a simple custom process dumper using MiniDumpWriteDump
API:
Create a minidump of the lsass.exe using task manager (must be running as administrator):
Swtich mimikatz context to the minidump:
Procdump from sysinternal's could also be used to dump the process:
Executing a native comsvcs.dll DLL found in Windows\system32 with rundll32:
Sometimes Cisco Jabber (always?) comes with a nice utility called ProcessDump.exe
that can be found in c:\program files (x86)\cisco systems\cisco jabber\x64\
. We can use it to dump lsass process memory in Powershell like so: