Skip to content

florylsk/NtDump

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 

Repository files navigation

NtDump

Description

LSASS process dumper with (mostly) NT API indirect syscalls. Currently undetected under many AV/EDR solutions.

Usage

.\NtDump.exe (Get-Process lsass).Id path_to_dump

Credits

https://github.com/Dec0ne/HWSyscalls/

Releases

No releases published

Packages

No packages published