Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Failed to parse lsass from Windows servers #7

Open
hackcatz opened this issue Nov 16, 2023 · 1 comment
Open

Failed to parse lsass from Windows servers #7

hackcatz opened this issue Nov 16, 2023 · 1 comment

Comments

@hackcatz
Copy link

I noticed that the tool does not work on latest versions of Windows servers. After searching a bit I found that the issue is the same as here antonioCoco/MalSeclogon#1. This is due to the trick described here https://rastamouse.me/dumping-lsass-with-duplicated-handles/. When the PID is 0 the dump is not performed correctly. I am not so familiar with Go but i hope that helps solved the issue easier.

When I tried to replace 0 with the lsass PID the dump was performed correctly.

@hackcatz hackcatz changed the title Failed to parse lsass on Windows servers Failed to parse lsass from Windows servers Nov 16, 2023
@richardschwabe
Copy link

Do you mean you provided --pid or did you do something else?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants