
LsassReflectDumping
This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…
memory-forensicspassword-attackspost-exploitation+1
218

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Free hands-on digital forensics labs for students and faculty

A post-exploitation powershell tool for extracting juicy info from memory.

Leaking kernel addresses from ETW consumers. Requires Administrator privileges.