
LsassReflectDumping
This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

This is the tool to dump the LSASS process on modern Windows 11

Red teaming tool to dump LSASS memory, bypassing basic countermeasures.

Exploits a KSLD anti-rootkit driver vulnerability (IOCTL 0x222044) to bypass PPL protection and access sensitive process memory, enabling local…

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Dump the memory of any PPL with a Userland exploit chain

This tool demonstrates the application of fundamental physics discoveries to cybersecurity.


Penetration testing utility and antivirus assessment tool.

PIC-based Lsass memory dumper using cloned handles to evade detection, producing obfuscated dumps with minimal memory footprint for red team…

Modern security products (CrowdStrike, Bitdefender, SentinelOne, etc.) hook the nLoadImage function inside clr.dll to intercept and scan in-memory…

Golang tool designed to exfiltrate passwords found via the sshd and su services

A post-exploitation powershell tool for extracting juicy info from memory.

The swiss army knife of LSASS dumping

Activation Context Hijacking Evasion Tool

Local Privilege Escalation PoC to pop a SYSTEM shell for CVE-2019-9702 in Symantec Encryption Desktop.

open-source jailbreaking tool for many iOS devices