NativeDump allows to dump the lsass process using only NTAPIs generating a Minidump file with only the streams needed to be parsed by tools like Mimikatz or Pypykatz (SystemInfo, ModuleList and Memory64List Streams).
NativeDump.exe [DUMP_FILE]
The tool has been tested against Windows 10 and 11 devices with the most common security solutions (Microsoft Defender for Endpoints, Crowdstrike…) and is for now undetected.
However, it does not work if PPL is enabled in the system.
Some benefits of this technique are:
The project has three branches at the moment (apart from the main branch with the basic technique):
After reading Minidump undocumented structures, its structure can be summed up to:
For more information here.
Cify is a Ruby-based WiFi hacking tool designed for penetration testers, security researchers, and network…
Dive into the world of cyber security with our exploration of VisionServices Multi-Tool. Developed in…
A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting. The…
Dive into the world of cybersecurity with GoHTools, a comprehensive collection of hacking utilities crafted…
DefGen allows you to create your personalized HTML defacing webpage pre-integrated with CSS and JavaScript.…
Dive into the world of colorlight-riscv-rs, where we embark on an exciting journey to manipulate…