bandicam.2024-04-21.15-10-00-222.mp4
"D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system calls, randomized procedures, and prototype name obfuscation.
- Just open the project solution in visual studio and compile it. If you are facing any issue regarding assembler then right click on solution and go to build customization and make sure MASM is selected.
- This tool will only work on windows with major version (10.0).
- This will only work when PPL protection is disabled.
- Use tools like mimikatz or pypykatz to read the hashes from dumped file.
-
Mimikatz
sekurlsa::minidump [filename] sekurlsa::logonpasswords
-
Pypykatz
pypykatz lsa minidump [filename]
This repository is only for educational purposes.