You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I noticed that the tool does not work on latest versions of Windows servers. After searching a bit I found that the issue is the same as here antonioCoco/MalSeclogon#1. This is due to the trick described here https://rastamouse.me/dumping-lsass-with-duplicated-handles/. When the PID is 0 the dump is not performed correctly. I am not so familiar with Go but i hope that helps solved the issue easier.
When I tried to replace 0 with the lsass PID the dump was performed correctly.
The text was updated successfully, but these errors were encountered:
hackcatz
changed the title
Failed to parse lsass on Windows servers
Failed to parse lsass from Windows servers
Nov 16, 2023
I noticed that the tool does not work on latest versions of Windows servers. After searching a bit I found that the issue is the same as here antonioCoco/MalSeclogon#1. This is due to the trick described here https://rastamouse.me/dumping-lsass-with-duplicated-handles/. When the PID is 0 the dump is not performed correctly. I am not so familiar with Go but i hope that helps solved the issue easier.
When I tried to replace 0 with the lsass PID the dump was performed correctly.
The text was updated successfully, but these errors were encountered: