redttps

Lsass Dump using System Informer

Description

This technique involves using a tool called System Informer to steal passwords and other sensitive login info from a Windows computer’s memory.


Steps

  1. Download tool: https://systeminformer.com/
  2. Open the tool > right-click on the lsass.exe process > minimal dump