πNew WriteupβοΈ
βββββββββββββββ
πDate: Wed, 02 Aug 2023 04:41:09 GMT
βββββββββββββββ
βοΈTitle: Red Team Shenanigans: Stealing Logon Credentials Without Touching LSASS
βββββββββββββββ
πLink: https://medium.com/p/1a73e1cfda3b
βββββββββββββββ
Tags: #evasion #lsass #active_directory #red_team #penetration_testing
βββββββββββββββ
πDate: Wed, 02 Aug 2023 04:41:09 GMT
βββββββββββββββ
βοΈTitle: Red Team Shenanigans: Stealing Logon Credentials Without Touching LSASS
βββββββββββββββ
πLink: https://medium.com/p/1a73e1cfda3b
βββββββββββββββ
Tags: #evasion #lsass #active_directory #red_team #penetration_testing
Medium
Red Team Shenanigans: Stealing Logon Credentials Without Touching LSASS
In this blog, weβll familiarize ourselves with some interesting methods via which we can obtain credentials for logged-on users. Itβsβ¦
β€· Title: POSTDump: perform minidump of LSASS process using few technics to avoid detection
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 03 Feb 2025 01:45:51 +0000
ββββββββββββββββββββββββ
β Tags: #Ethical Hacking #LSASS process #MiniDump #POSTDump
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 03 Feb 2025 01:45:51 +0000
ββββββββββββββββββββββββ
β Tags: #Ethical Hacking #LSASS process #MiniDump #POSTDump
Penetration Testing Tools
POSTDump: perform minidump of LSASS process using few technics to avoid detection
POSTDump is an another tool to perform minidump of LSASS process using few techniques to avoid detection.
β€· Title: Protecting Cached Credentials with Advanced Auditing
ββββββββββββββββββββββββ
πͺ Author: Horizon Secured
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 19 Feb 2025 11:25:58 GMT
ββββββββββββββββββββββββ
β Tags: #windows_security #lsass #advanced_auditing #windows #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Horizon Secured
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 19 Feb 2025 11:25:58 GMT
ββββββββββββββββββββββββ
β Tags: #windows_security #lsass #advanced_auditing #windows #cybersecurity
Medium
Protecting Cached Credentials with Advanced Auditing
Keep your cached credentials safe from attackers! In this guide, learn how to set up Windows Advanced Auditing to detect unauthorizedβ¦
β€· Title: Intrusion Detection With Splunk (Real-world Scenario)
ββββββββββββββββββββββββ
πͺ Author: M_ΨΉtt@
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 21 Apr 2025 23:20:07 GMT
ββββββββββββββββββββββββ
β Tags: #lsass #dumping #splunk_enterprise #splunk #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: M_ΨΉtt@
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 21 Apr 2025 23:20:07 GMT
ββββββββββββββββββββββββ
β Tags: #lsass #dumping #splunk_enterprise #splunk #cybersecurity
Medium
Intrusion Detection With Splunk (Real-world Scenario)
Hello again π! In this article, We will answer a set of questions from a real scenario using SPL in Splunk. There are five questions inβ¦
β€· Title: ComDotNetExploit: PoC for Windows PPL Bypass via COM-to-.NET
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 25 May 2025 01:30:03 +0000
ββββββββββββββββββββββββ
β Tags: #Ethical Hacking #.NET #code injection #COM #cybersecurity #exploit #LSASS #PPL #reflection #Windows Security
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 25 May 2025 01:30:03 +0000
ββββββββββββββββββββββββ
β Tags: #Ethical Hacking #.NET #code injection #COM #cybersecurity #exploit #LSASS #PPL #reflection #Windows Security
Penetration Testing Tools
ComDotNetExploit: PoC for Windows PPL Bypass via COM-to-.NET
ComDotNetExploit is a C++ PoC demonstrating PPL bypass in Windows using COM-to-.NET redirection and reflection for code injection.
β€· Title: Mimikatz CheatsheetβββPractical Credential Dumping Guide from Labs & Real-World Scenarios
ββββββββββββββββββββββββ
πͺ Author: Mohamed Ashraf
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 04 Jul 2025 13:58:55 GMT
ββββββββββββββββββββββββ
β Tags: #penetration_testing #lsass #red_team #cybersecurity #mimikatz
ββββββββββββββββββββββββ
πͺ Author: Mohamed Ashraf
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 04 Jul 2025 13:58:55 GMT
ββββββββββββββββββββββββ
β Tags: #penetration_testing #lsass #red_team #cybersecurity #mimikatz
Medium
Mimikatz Cheatsheet β Practical Credential Dumping Guide from Labs & Real-World Scenarios
@Mx0o14
β€· Title: NativeDump: Stealthy LSASS Dumping Tool Bypasses EDRs Using Only NTAPIs
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 21 Jul 2025 00:29:01 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #credential dumping #cybersecurity #Evasion #LSASS #Mimikatz #NativeDump #Offensive Security #pypykatz #Red Team #Windows Security
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 21 Jul 2025 00:29:01 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #credential dumping #cybersecurity #Evasion #LSASS #Mimikatz #NativeDump #Offensive Security #pypykatz #Red Team #Windows Security
Penetration Testing Tools
NativeDump: Stealthy LSASS Dumping Tool Bypasses EDRs Using Only NTAPIs
NativeDump is a new tool for stealthy LSASS process dumping using only NTAPIs, bypassing EDRs to extract credentials for tools like Mimikatz or Pypykatz.
β€· Title: HTB_Academy: Extracting Passwords from Windows Systems Part 2:Attacking LSASS
ββββββββββββββββββββββββ
πͺ Author: Babatunde Ojo
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 15 Oct 2025 18:09:04 GMT
ββββββββββββββββββββββββ
β Tags: #windows #htb #hacking #passwords #lsass
ββββββββββββββββββββββββ
πͺ Author: Babatunde Ojo
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 15 Oct 2025 18:09:04 GMT
ββββββββββββββββββββββββ
β Tags: #windows #htb #hacking #passwords #lsass
Medium
HTB_Academy: Extracting Passwords from Windows Systems Part 2:Attacking LSASS
LSASS is a core Windows process responsible for enforcing security policies, handling user authentication, and storing sensitive credentialβ¦
β€· Title: LSASS-Free Larceny: Extracting NTLMv1 Hashes with DumpGuard BOF
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 12 Jan 2026 04:51:09 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #BOF #credential dumping #Cybersecurity 2026 #DumpGuard #Havoc C2 #LSASS #NTLMv1 #red teaming #Remote Credential Guard #Windows Security
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 12 Jan 2026 04:51:09 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #BOF #credential dumping #Cybersecurity 2026 #DumpGuard #Havoc C2 #LSASS #NTLMv1 #red teaming #Remote Credential Guard #Windows Security
Information Security News
LSASS-Free Larceny: Extracting NTLMv1 Hashes with DumpGuard BOF
DumpGuard BOF Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems. This repository contains a Beacon Object File (BOF) implementation ofβ¦
β€· Title: Patch Tuesday Jan 2026: Microsoft Fixes 114 Flaws & 3 Zero-Days
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 14 Jan 2026 00:11:47 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #Agere Soft Modem #CISA #CVE_2026_20805 #LSASS #Microsoft #Office Vulnerability #Patch Tuesday #Secure Boot #Windows Security #zero_day
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 14 Jan 2026 00:11:47 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability Report #Agere Soft Modem #CISA #CVE_2026_20805 #LSASS #Microsoft #Office Vulnerability #Patch Tuesday #Secure Boot #Windows Security #zero_day
Daily CyberSecurity
Patch Tuesday Jan 2026: Microsoft Fixes 114 Flaws & 3 Zero-Days
Microsoft Jan 2026 Patch Tuesday fixes 114 flaws, including 3 zero-days. CVE-2026-20805 is actively exploited. Update Windows & Office immediately.
β€· Title: Microsoftβs 2026 Kickoff: 110+ Patches Fix Active Zero-Days and Office Flaws
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 15 Jan 2026 08:24:36 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #Windows #CVE_2026_20805 #cybersecurity #Infosec News #LSASS #Microsoft #Office 2026 #Patch Tuesday #RCE #Secure Boot #Windows 11 #zero_day
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 15 Jan 2026 08:24:36 +0000
ββββββββββββββββββββββββ
β Tags: #Vulnerability #Windows #CVE_2026_20805 #cybersecurity #Infosec News #LSASS #Microsoft #Office 2026 #Patch Tuesday #RCE #Secure Boot #Windows 11 #zero_day
Penetration Testing Tools
Microsoft's 2026 Kickoff: 110+ Patches Fix Active Zero-Days and Office Flaws
Microsoft has inaugurated its first Patch Tuesday of 2026, disseminating a comprehensive suite of mandatory security remediations for
β€· Title: Screaming at the Kernel: How GhostKatz Uses βVulnerable Driversβ to Dump Credentials via Physical Memory
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Feb 2026 04:00:10 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #Aggressor Script #BYOVD #Cobalt Strike #credential exfiltration #Erik Esquivel #GhostKatz #Julian PeΓ±a #kernel exploitation #LSASS dump #MmMapIoSpace #red team tools #Tech News 2026
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Feb 2026 04:00:10 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #Aggressor Script #BYOVD #Cobalt Strike #credential exfiltration #Erik Esquivel #GhostKatz #Julian PeΓ±a #kernel exploitation #LSASS dump #MmMapIoSpace #red team tools #Tech News 2026
Information Security News
Screaming at the Kernel: How GhostKatz Uses βVulnerable Driversβ to Dump Credentials via Physical Memory
Security researcher Julian PeΓ±a has unveiled GhostKatz, a formidable new utility engineered to exfiltrate credentials from the LSASS process by directly accessing a computerβs physical memorβ¦
β€· Title: Targeting the Grid: ESET Unmasks βDynoWiperβ After Destructive Strike on Polish Energy Sector
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Feb 2026 03:50:20 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Active Directory GPO #Critical Infrastructure #cyber sabotage #data wiper #DynoWiper #ESET research #LSASS memory dump #Poland energy sector #rsocx #Rubeus #Sandworm #Tech News 2026 #ZOV wiper
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Feb 2026 03:50:20 +0000
ββββββββββββββββββββββββ
β Tags: #Cyber Security #Active Directory GPO #Critical Infrastructure #cyber sabotage #data wiper #DynoWiper #ESET research #LSASS memory dump #Poland energy sector #rsocx #Rubeus #Sandworm #Tech News 2026 #ZOV wiper
Penetration Testing Tools
Targeting the Grid: ESET Unmasks "DynoWiper" After Destructive Strike on Polish Energy Sector
ESET has disclosed the intricate technical specifications of an incursion involving a nascent data-obliteration utility designated as DynoWiper.
β€· Title: Beyond the Memory: How LSA Whisperer BOF Bypasses PPL and Credential Guard Without Touching LSASS
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 23 Feb 2026 03:04:12 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #BOF #Cloud SSO #Cobalt Strike #Credential Guard #DPAPI #Kerberos #LSA Whisperer #LsaCallAuthenticationPackage #LSASS #Pentesting #PPL #red teaming #SpecterOps #Windows Security
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 23 Feb 2026 03:04:12 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #BOF #Cloud SSO #Cobalt Strike #Credential Guard #DPAPI #Kerberos #LSA Whisperer #LsaCallAuthenticationPackage #LSASS #Pentesting #PPL #red teaming #SpecterOps #Windows Security
Penetration Testing Tools
Beyond the Memory: How LSA Whisperer BOF Bypasses PPL and Credential Guard Without Touching LSASS
Interact with Kerberos and DPAPI without opening an LSASS handle. LSA Whisperer BOF uses official APIs to bypass PPL and Credential Guard during red teaming.
β€· Title: Attacking LSASS: HackTheBox Walkthrough | Peneteration Tester Path
ββββββββββββββββββββββββ
πͺ Author: zerodaystudios
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 26 Feb 2026 03:41:00 GMT
ββββββββββββββββββββββββ
β Tags: #penetration_testing #hacking #lsass #ethical_hacking #windows
ββββββββββββββββββββββββ
πͺ Author: zerodaystudios
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 26 Feb 2026 03:41:00 GMT
ββββββββββββββββββββββββ
β Tags: #penetration_testing #hacking #lsass #ethical_hacking #windows
Medium
Attacking LSASS: HackTheBox Walkthrough | Peneteration Tester Path
Step 1: Creating an LSASS Memory Dump (Task Manager Method)