SkillAgentSearch skills...

LsassSilentProcessExit

Command line interface to dump LSASS memory to disk via SilentProcessExit

Install / Use

/learn @deepinstinct/LsassSilentProcessExit
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

LsassSilentProcessExit

New method of causing WerFault.exe to dump lsass.exe process memory to disk for credentials extraction via silent process exit mechanism without crasing lsass.exe.

Usage:
LsassSilentProcessExit.exe <PID of LSASS.exe> <DumpMode>

Where DumpMode can be:

  0 - Call RtlSilentProcessExit on LSASS process handle
  1 - Call CreateRemoteThread on RtlSilentProcessExit on LSASS

Related Skills

View on GitHub
GitHub Stars455
CategoryDevelopment
Updated3d ago
Forks63

Languages

C++

Security Score

80/100

Audited on Mar 29, 2026

No findings