
LsassReflectDumping
This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…
memory-forensicspassword-attackspost-exploitation+1
218

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.

A post-exploitation powershell tool for extracting juicy info from memory.

Free hands-on digital forensics labs for students and faculty