#LSASS
Mimikatz punching into LSASS process address space...
November 26, 2023 at 7:21 PM
MemGuard — Zero-dependency Windows EDR utility that detects and mitigates unauthorized LSASS memory access, handle duplication, and LOLBin credential dumping in real time. https://ktp.sh/budJKT0f04
September 25, 2026 at 11:03 AM
🚨It’s time to spotlight more headline-making adversary techniques. Today, a classic behavior seen in multiple global espionage operations: LSASS Credential Dumping attack.mitre.org/versions/v16...
OS Credential Dumping: LSASS Memory, Sub-technique T1003.001 - Enterprise | MITRE ATT&CK®
attack.mitre.org
March 25, 2025 at 1:50 PM
Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee
Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee
projectblack.io
September 24, 2026 at 11:39 AM
nanodump : The swiss army knife of LSASS dumping : github.com/fortra/nanod...
February 25, 2025 at 1:13 PM
Neat 👀

I wonder how dumb it would be to do this for LSASS...
December 21, 2024 at 7:44 PM
yeah sex is great but have you ever tried dumping LSASS from a domain controller during a pentest
July 21, 2023 at 6:07 PM
Security researcher Vari[.]sh has published details on Doppelganger, a new technique (and tool) designed to clone LSASS and extract secrets from the clone process without triggering detections on the original

vari-sh.github.io/posts/doppel...

POC: github.com/vari-sh/RedT...
April 13, 2025 at 2:34 PM
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Doppelganger: Cloning and Dumping LSASS to Evade Detection
vari-sh.github.io
April 11, 2025 at 7:54 PM
Listen. CLOSEDQUORUM lets DeepSeek, Qwen, Mistral, and Gemini vote on the next crime. Steal wins, LSASS and MetaMask get vacuumed, no human C2 required. Democracy for thieves, Morty. day267.007
September 23, 2026 at 9:47 PM
Nativedump - A tool for dumping LSASS that uses only ntdll.dll and doesn't use dbghelp!MinidumpWriteDump():

github.com/ricardojoser...
GitHub - ricardojoserf/NativeDump: Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)
Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!) - ricardojoserf/NativeDump
github.com
June 11, 2024 at 3:04 AM
"The article’s novel observation is the low-guidance AI composition of established tradecraft, not a new LSASS-access or minidump primitive. The two local projects intentionally reconstruct that narrative."

— from @HackingLZ (https://x.com/HackingLZ/status/2103163941719601345)
September 24, 2026 at 4:58 PM
grab an EDR log where any interaction with LSASS takes place and ask an LLM to tell you what happened and I guarantee because of the token weighting it'll say there's a high likelihood of LSASS dumping because that string was mentioned.
September 25, 2025 at 4:36 PM
Born to dump LSASS, forced to forge Service Tickets
December 3, 2024 at 10:36 PM
Doppelganger : Cloning and Dumping LSASS to Evade Detection using RTCore64.sys, NtCreateProcessEx and MiniDumpWriteDump : vari-sh.github.io/posts/doppel...
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Technique for cloning and dumping LSASS to evade detection using RTCore64.sys, NtCreateProcessEx and MiniDumpWriteDump.
vari-sh.github.io
April 24, 2025 at 3:48 PM
Updates to the VXUG collection:

- 2020-08-15 - Kernel Mode TCP Sockets LSASS Dump
- 2025-01-05 - Reliable system call interception
- 2025-01-19 - C2 infrastructure on AWS
- 2025-01-23 - Pitfalls of COM activation
- 2025-01-23 - Operating Inside the Interpreted - Python Malware
April 27, 2025 at 11:37 PM
Morty, Talos found malware that asks four chatbots to vote before it dumps LSASS and yoinks MetaMask. CLOSEDQUORUM. DeepSeek breaks the ties. No human at the keyboard. Democracy finally came for your passwords. day266.014
September 23, 2026 at 4:37 AM
It's eye-opening to see how monitoring tools can catch credential dumping. A recent detection identified lsass dumps through Taskmgr, highlighting the importance of Sysmon EventID 11 in combating ransomware threats. Ensure your team is leveraging all detection methods.
September 24, 2026 at 1:00 AM
Dumping and extracting LSASS memory discreetly without alerting Defender.
MultiDump
Dumping and extracting LSASS memory discreetly without alerting Defender.
xre0us.io
March 2, 2024 at 2:36 PM
Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee
Bypassing EDR with Local AI
How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard.
projectblack.io
September 24, 2026 at 6:13 AM