timwhitez starred Lsass-Shtinkering
2022-8-26 16:59:2 Author: github.com(查看原文) 阅读量:57 收藏

New method of dumping LSASS by abusing the Windows Error Reporting service. It sends a message to the service with the ALPC protocol to report an exception on LSASS. This report will cause the service to dump the memory of LSASS.

Prerequisites

The registry value "DumpType" under "HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps" should be set to 2.

Credits

References


文章来源: https://github.com/deepinstinct/Lsass-Shtinkering
如有侵权请联系:admin#unsafe.sh