#lsass
Mimikatz punching into LSASS process address space...
November 26, 2023 at 7:21 PM
MemGuard — Zero-Dependency LSASS Memory Shield & EDR Hook Detector
MemGuard — Zero-Dependency LSASS Memory Shield & EDR Hook Detector
github.com
September 27, 2026 at 7:09 AM
Local AI makes stealthy LSASS dumper that slips past two EDRs—an endpoint security alarm. #EDR #LocalAI #LSASS #DeepSeek #EndpointSecurity #Cybersecurity https://thedailytechfeed.com/local-ai-evades-edr-by-tweaking-lsass-dumper-locally/
September 26, 2026 at 4:57 PM
MemGuard — Zero-dependency Windows EDR utility that detects and mitigates unauthorized LSASS memory access, handle duplication, and LOLBin credential dumping in real time. https://ktp.sh/budJKT0f04
September 25, 2026 at 11:03 AM
Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials gbhackers.com/uncensored-l...
Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials
A new demonstration shows how a locally hosted, uncensored AI model can help generate a Windows LSASS credential-dumping utility that reportedly evaded endpoint detection and response products during ...
gbhackers.com
September 27, 2026 at 10:46 AM
🚨It’s time to spotlight more headline-making adversary techniques. Today, a classic behavior seen in multiple global espionage operations: LSASS Credential Dumping attack.mitre.org/versions/v16...
OS Credential Dumping: LSASS Memory, Sub-technique T1003.001 - Enterprise | MITRE ATT&CK®
attack.mitre.org
March 25, 2025 at 1:50 PM
nanodump : The swiss army knife of LSASS dumping : github.com/fortra/nanod...
February 25, 2025 at 1:13 PM
Neat 👀

I wonder how dumb it would be to do this for LSASS...
December 21, 2024 at 7:44 PM
Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee
Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee
projectblack.io
September 24, 2026 at 11:39 AM
yeah sex is great but have you ever tried dumping LSASS from a domain controller during a pentest
July 21, 2023 at 6:07 PM
MemGuard - Zero-Dependency LSASS Memory Shield & EDR Hook Detector
https://t.co/WUGYxYQcYE

— from @ipurple (https://x.com/ipurple/status/2103841545078165521)
GitHub - prox0959/MemGuard
t.co
September 26, 2026 at 1:53 PM
Security researcher Vari[.]sh has published details on Doppelganger, a new technique (and tool) designed to clone LSASS and extract secrets from the clone process without triggering detections on the original

vari-sh.github.io/posts/doppel...

POC: github.com/vari-sh/RedT...
April 13, 2025 at 2:34 PM
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Doppelganger: Cloning and Dumping LSASS to Evade Detection
vari-sh.github.io
April 11, 2025 at 7:54 PM
Nativedump - A tool for dumping LSASS that uses only ntdll.dll and doesn't use dbghelp!MinidumpWriteDump():

github.com/ricardojoser...
GitHub - ricardojoserf/NativeDump: Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)
Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!) - ricardojoserf/NativeDump
github.com
June 11, 2024 at 3:04 AM
grab an EDR log where any interaction with LSASS takes place and ask an LLM to tell you what happened and I guarantee because of the token weighting it'll say there's a high likelihood of LSASS dumping because that string was mentioned.
September 25, 2025 at 4:36 PM
Born to dump LSASS, forced to forge Service Tickets
December 3, 2024 at 10:36 PM
Doppelganger : Cloning and Dumping LSASS to Evade Detection using RTCore64.sys, NtCreateProcessEx and MiniDumpWriteDump : vari-sh.github.io/posts/doppel...
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Technique for cloning and dumping LSASS to evade detection using RTCore64.sys, NtCreateProcessEx and MiniDumpWriteDump.
vari-sh.github.io
April 24, 2025 at 3:48 PM
Updates to the VXUG collection:

- 2020-08-15 - Kernel Mode TCP Sockets LSASS Dump
- 2025-01-05 - Reliable system call interception
- 2025-01-19 - C2 infrastructure on AWS
- 2025-01-23 - Pitfalls of COM activation
- 2025-01-23 - Operating Inside the Interpreted - Python Malware
April 27, 2025 at 11:37 PM
Dumping and extracting LSASS memory discreetly without alerting Defender.
MultiDump
Dumping and extracting LSASS memory discreetly without alerting Defender.
xre0us.io
March 2, 2024 at 2:36 PM
I'm slowly making my way through tearing apart this ancient release of Windows NT, and I have a silly goal.

Back in the day, I used to work on Mono, and I'm half-tempted to try to port the runtime to the native API so that I can rewrite SMSS, LSASS, CSRSS, and friends in ordinary C#.
April 23, 2024 at 2:50 AM