BOF-ForeignLsass

LSASS Dumper

A tool for duplicating an existing process's handle to LSASS, allowing dumping of the local session store.

GitHub

98 stars
2 watching
25 forks
Language: C
last commit: about 5 years ago

Related projects:

RepositoryDescriptionStars
outflanknl/dumpertA tool for creating a low-level memory dump of the LSASS process using direct system calls and API unhooking.1,496
seventeenman/callbackdumpA utility that allows dumping the memory of the LSASS process without triggering antivirus signatures or sandbox detection.548
hagrid29/duplicatedumpTools to dump LSASS memory without detection using custom LSA plugin and duplicated handle199
fortra/nanodumpCreates a minidump of the LSASS process1,813
deepinstinct/lsass-shtinkeringExploits Windows Error Reporting to dump LSASS memory378
espressocake/ppldump_bofA tool for dumping the memory contents of a protected process on Windows136
codewhitesec/handlekatzA tool that uses cloned handles to create an obfuscated memory dump of the Lsass process.575
xforcered/credbanditA proof-of-concept tool for dumping the memory of a process and sending it back through a custom communication channel.233
octoberfest7/dropspawn_bofA CobaltStrike payload that uses DLL hijacking to spawn additional Beacons on Windows systems219
m57/cobaltstrike_bofsExploits SeBackupPrivilege to dump remote system hives and credentials.159
anott03/nvim-lspinstallA replacement for neovim's :LspInstall function to install language servers for its built-in lsp.88
otterhacker/coffloaderAn implementation of in-house CoffLoader supporting CobaltStrike standard BOF and BSS initialized variables.48
yireo/yireo_dumpcmscontentA Magento 2 module to dump CMS pages and blocks to a folder for Tailwind CSS configuration16
alexandernst/memory-dumperA tool for extracting data from process memory36
netero1010/servicemove-bofA tool that exploits a Windows vulnerability to execute arbitrary code on remote systems using a technique called DLL hijacking.284