Dumping Lsass Without Mimikatz
PreviousDumping Credentials from Lsass Process Memory with MimikatzNextDumping Lsass without Mimikatz with MiniDumpWriteDump
Last updated
Last updated
See my notes about writing a simple custom process dumper using MiniDumpWriteDump
API:
Create a minidump of the lsass.exe using task manager (must be running as administrator):
Swtich mimikatz context to the minidump:
Procdump from sysinternal's could also be used to dump the process:
Executing a native comsvcs.dll DLL found in Windows\system32 with rundll32:
Sometimes Cisco Jabber (always?) comes with a nice utility called ProcessDump.exe
that can be found in c:\program files (x86)\cisco systems\cisco jabber\x64\
. We can use it to dump lsass process memory in Powershell like so: