This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process.
Once the clone is created, it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process.
Simply execute the compiled file.
ReflectDump.exe Use Mimikatz or Pypykatz to parse the dump file offline.
sekurlsa::minidump [filename] sekurlsa::logonpasswords
pypykatz lsa minidump [filename] * Encrypt dump before writing on disk to bypass static detection.
* Exfiltrate on C2 Server Samba is a free, open-source implementation of the SMB/CIFS network protocol that lets Linux servers share…
Running your own VPN gives you full control over your traffic, privacy, and connection security. It encrypts…
IntelliJ IDEA is a full-featured IDE for JVM and Android development made by JetBrains. It includes…
Steam is a cross-platform digital distribution platform by Valve Corporation that gives you access to thousands…
Redmine is one of the most popular open-source project management and issue tracking platforms. It is…
VirtualBox is a free, open-source, cross-platform virtualization application maintained by Oracle. It lets you run multiple…