[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFpIp-5cIqjL8UPkywqYgeK0zaeUCBreDnhrEM5ZZmuI":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},819,"How do you install Lsassy and fix formatting issues on Windows?","Lsassy can be installed using pip: `pip install lsassy`. However, on Windows, the default output may contain garbled characters due to `termcolor` coloring not displaying properly in cmd. To fix this, modify the `logger.py` file located at `lib\\site-packages\\lsassy\\logger.py` to check the OS and set color codes to empty strings on Windows (nt). The provided code in the article adjusts the formatter accordingly. After this modification, the tool can be tested with a command like `lsassy -u Administrator -p Password1 192.168.1.1`.","\u003Cp>Lsassy can be installed using pip: `pip install lsassy`. However, on Windows, the default output may contain garbled characters due to `termcolor` coloring not displaying properly in cmd. To fix this, modify the `logger.py` file located at `lib\\site-packages\\lsassy\\logger.py` to check the OS and set color codes to empty strings on Windows (nt). The provided code in the article adjusts the formatter accordingly. After this modification, the tool can be tested with a command like `lsassy -u Administrator -p Password1 192.168.1.1`.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-remotely-extracting-credentials-from-the-lsass-exe-process\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-you-install-lsassy-and-fix-formatting-issues-on-windows-1777481782701","lsassy installation, Windows formatting, termcolor, logger.py",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},201,"Penetration Basics - Remotely Extracting Credentials from the lsass.exe Process","penetration-basics-remotely-extracting-credentials-from-the-lsass-exe-process","Learn how to remotely extract credentials from lsass.exe using lsassy tool. Methods for remote command execution, parsing password hashes, and automation in penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Basics - Extracting Credentials from the lsass.exe Process', methods for locally extracting credentials were introduced. However, in penetration testing, it is often necessary to extract credentials remotely. This article will discuss the concepts and methods for remote credential extraction, detailing the specifics.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Concepts\u003C\u002Fli>\u003Cli>Implementation Methods\u003C\u002Fli>\u003Cli>Introduction to lsassy\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When extracting credentials remotely, the following points need to be considered:\u003C\u002Fp>\u003Cp>(1) Remote command execution must be achieved. For remote command execution, refer to the previous article 'Techniques for Executing Programs on Remote Systems'.\u003C\u002Fp>\u003Cp>(2) Due to protective measures, different environments require different extraction methods.\u003C\u002Fp>\u003Cp>(3) After remotely exporting the dump file of the lsass process, it is common to copy the dump file locally to parse and obtain password hashes. Sometimes, the lsass process dump file is large, so the efficiency of file transfer needs to be considered.\u003C\u002Fp>\u003Cp>(4) For multiple systems, repetitive tasks are too frequent, resulting in low efficiency.\u003C\u002Fp>\u003Cp>Considering the above points, we need a convenient and quick method: support multiple export methods, directly parse password hashes, and automate operations to improve efficiency.\u003C\u002Fp>\u003Cp>The open-source tool Lsassy can be used here, available at: https:\u002F\u002Fgithub.com\u002FHackndo\u002Flsassy\u003C\u002Fp>\u003Ch2>0x03 Introduction to Lsassy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Installation and Usage\u003C\u002Fh3>\u003Cp>Installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pip install lsassy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsassy -u Administrator -p Password1 192.168.1.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the output, colors are added using termcolor. By default, Windows cmd cannot display colors properly, leading to unfriendly formatting and some garbled characters.\u003C\u002Fp>\u003Cp>To solve the formatting issue on Windows, modify \u003Cpython>\\lib\\site-packages\\lsassy\\logger.py with the following code:\u003C\u002Fpython>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import logging\u003Cbr>import os\u003Cbr>import sys\u003Cbr>class LsassyFormatter(logging.Formatter):\u003Cbr>    def __init__(self):\u003Cbr>        logging.Formatter.__init__(self, '%(bullet)s %(threadName)s %(message)s', None)\u003Cbr>        if os.name == 'nt':\u003Cbr>            self.BLUE, self.WHITE, self.YELLOW, self.RED, self.NC = '', '', '', '', ''\u003Cbr>        else:\u003Cbr>            self.BLUE = '\\033[1;34m'\u003Cbr>            self.WHITE = '\\033[1;37m'\u003Cbr>            self.YELLOW = '\\033[1;33m'\u003Cbr>            self.RED = '\\033[1;31m'\u003Cbr>            self.GREEN = '\\033[1;32m'\u003Cbr>            self.NC = '\\033[0m'\u003Cbr>    def format(self, record):\u003Cbr>        if record.levelno == logging.INFO:\u003Cbr>            record.bullet = '[*]{}'.format(self.NC)\u003Cbr>        elif record.levelno == logging.DEBUG:\u003Cbr>            record.bullet = '[*]{}'.format(self.NC)\u003Cbr>        elif record.levelno == logging.WARNING:\u003Cbr>            record.bullet = '[!]{}'.format(self.NC)\u003Cbr>        elif record.levelno == logging.ERROR:\u003Cbr>            record.bullet = '[x]{}'.format(self.NC)\u003Cbr>        else:\u003Cbr>            record.bullet = '[+]{}'.format(self.NC)\u003Cbr>        if record.exc_info and logging.getLogger().getEffectiveLevel() != logging.DEBUG:\u003Cbr>            record.exc_info = None\u003Cbr>        return logging.Formatter.format(self, record)\u003Cbr>def highlight(msg):\u003Cbr>    return msg\u003Cbr>def init(quiet=False):\u003Cbr>    handler = logging.StreamHandler(sys.stdout)\u003Cbr>    handler.setFormatter(LsassyFormatter())\u003Cbr>    logging.getLogger().addHandler(handler)\u003Cbr>    logging.getLogger().setLevel(logging.INFO)\u003Cbr>    logging.addLevelName(25, 'SUCCESS')\u003Cbr>    setattr(logging, 'success', lambda message, *args: logging.getLogger()._log(25, message, args))\u003Cbr>    logging.getLogger().disabled = quiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Package into exe\u003C\u002Fh3>\u003Cp>PyInstaller can be used here, the main program code is at https:\u002F\u002Fgithub.com\u002FHackndo\u002Flsassy\u002Fblob\u002Fmaster\u002Flsassy\u002Fconsole.py\u003C\u002Fp>\u003Cp>Command to package into a standalone exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyinstaller -F console.py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After generating console.exe, an error will be reported during execution indicating missing modules\u003C\u002Fp>\u003Cp>Modify the packaging command based on the output prompts, adding referenced modules:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyinstaller -F console.py --hidden-import unicrypto.backends.pure.DES --hidden-import unicrypto.backends.pure.TDES --hidden-import unicrypto.backends.pure.AES --hidden-import unicrypto.backends.pure.RC4\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, although console.exe can start normally, the export function cannot run\u003C\u002Fp>\u003Cp>Debugging method: Add the parameter -vv to see that lsassy.dumpmethod.comsvcs cannot be found\u003C\u002Fp>\u003Cp>Add all dependency packages to get the complete packaging command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyinstaller -F console.py --hidden-import unicrypto.backends.pure.DES --hidden-import unicrypto.backends.pure.TDES --hidden-import unicrypto.backends.pure.AES --hidden-import unicrypto.backends.pure.RC4 --hidden-import lsassy.dumpmethod.comsvcs --hidden-import lsassy.dumpmethod.comsvcs_stealth --hidden-import lsassy.dumpmethod.dllinject --hidden-import lsassy.dumpmethod.dumpert --hidden-import lsassy.dumpmethod.dumpertdll --hidden-import lsassy.dumpmethod.edrsandblast --hidden-import lsassy.dumpmethod.mirrordump --hidden-import lsassy.dumpmethod.mirrordump_embedded --hidden-import lsassy.dumpmethod.nanodump --hidden-import lsassy.dumpmethod.ppldump --hidden-import lsassy.dumpmethod.ppldump_embedded --hidden-import lsassy.dumpmethod.procdump --hidden-import lsassy.dumpmethod.procdump_embedded --hidden-import lsassy.dumpmethod.rdrleakdiag --hidden-import lsassy.dumpmethod.wer --hidden-import lsassy.exec.mmc --hidden-import lsassy.exec.smb --hidden-import lsassy.exec.smb_stealth --hidden-import lsassy.exec.task --hidden-import lsassy.exec.wmi --hidden-import lsassy.output.grep_output --hidden-import lsassy.output.json_output --hidden-import lsassy.output.pretty_output --hidden-import lsassy.output.table_output\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The generated console.exe can now be used normally\u003C\u002Fp>\u003Ch3>3. Supported export methods\u003C\u002Fh3>\u003Ch4>(1) comsvcs\u003C\u002Fh4>\u003Cp>Use the export function MiniDump() from C:\\windows\\system32\\comsvcs.dll to obtain a dump file of the lsass process\u003C\u002Fp>\u003Cp>For details, refer to the previous article \"MiniDumpWriteDump via COM+ Services DLL\" for exploitation testing\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(2) comsvcs_stealth\u003C\u002Fh4>\u003Cp>Similar to comsvcs, the difference is to first copy C:\\windows\\system32\\comsvcs.dll to c:\\windows\\temp and rename it, then use the new dll to obtain a dump file of the lsass process\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(3) dllinject\u003C\u002Fh4>\u003Cp>Implemented through DLL injection\u003C\u002Fp>\u003Cp>For the APC injection method, refer to \"DLL Injection via APC—Bypassing Sysmon Monitoring\"\u003C\u002Fp>\u003Cp>Required parameter: -O loader_path=loader.exe,dll_path=inject.dll\u003C\u002Fp>\u003Ch4>(4) dumpert\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002Foutflanknl\u002FDumpert\u003C\u002Fp>\u003Cp>Obtain dump file of lsass process via API MiniDumpWriteDump()\u003C\u002Fp>\u003Cp>Required parameter: -O dumpert_path=dumpert.exe\u003C\u002Fp>\u003Ch4>(5) dumpertdll\u003C\u002Fh4>\u003Cp>Same method as above, difference is using dll file as parameter\u003C\u002Fp>\u003Cp>Required parameter: -O dumpertdll_path=dumpert.dll\u003C\u002Fp>\u003Ch4>(6) edrsandblast\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002Fwavestone-cdt\u002FEDRSandblast\u003C\u002Fp>\u003Cp>Obtain lsass process dump file using signed driver\u003C\u002Fp>\u003Cp>Required parameter: -O edrsandblast_path=EDRSandBlast.exe,RTCore64_path=RTCore64.sys,ntoskrnl_path=NtoskrnlOffsets.csv\u003C\u002Fp>\u003Ch4>(7) mirrordump\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002FCCob\u002FMirrorDump\u003C\u002Fp>\u003Cp>Implementation process:\u003C\u002Fp>\u003Cul>\u003Cli>Load an LSA SSP plugin\u003C\u002Fli>\u003Cli>Leak the process handle of lsass.exe within the plugin\u003C\u002Fli>\u003Cli>Obtain the dump file of the lsass process via the API MiniDumpWriteDump()\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Requires adding the parameter: -O mirrordump_path=Mirrordump.exe\u003C\u002Fp>\u003Ch4>(8) mirrordump_embedded\u003C\u002Fh4>\u003Cp>Method is the same as above, Mirrordump.exe is not required as a parameter\u003C\u002Fp>\u003Cp>Note that mirrordump cannot automatically clear the registered LSA SSP plugin; using this method will leave the following traces:\u003C\u002Fp>\u003Cul>\u003Cli>The LSA SSP plugin is saved in C:\\Windows\\System32, with an eight-character random name and a .dll extension\u003C\u002Fli>\u003Cli>Residual unloaded dll in the lsass process\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Traces are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017249815_0_b461d80d2e.jpeg\">\u003C\u002Fp>\u003Cp>Method to clear traces: first unload the dll loaded in the lsass process, then delete the dll file\u003C\u002Fp>\u003Cp>For details on enumerating and clearing LSA SSP plugins, refer to the previous article 'Usage of SSP in Mimikatz'\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(9) nanodump\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002Fhelpsystems\u002Fnanodump\u003C\u002Fp>\u003Cp>Advantage: supports multiple methods to leak lsass process handles\u003C\u002Fp>\u003Cp>Required parameter: -O nanodump_path=nanodump.exe\u003C\u002Fp>\u003Ch4>(10) ppldump\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002Fitm4n\u002FPPLdump\u003C\u002Fp>\u003Cp>Supports Windows 10 and Server 2019\u003C\u002Fp>\u003Cp>Can bypass PPL (Protected Process Light) protection for lsass process\u003C\u002Fp>\u003Cp>Related details:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fitm4n.github.io\u002Flsass-runasppl\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.scrt.ch\u002F2021\u002F04\u002F22\u002Fbypassing-lsa-protection-in-userland\u002F\u003C\u002Fp>\u003Cp>Required parameter: -O ppldump_path=PPLdump.exe\u003C\u002Fp>\u003Ch4>(11) ppldump_embedded\u003C\u002Fh4>\u003Cp>Same method as above, does not require PPLdump.exe as parameter\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(12) procdump\u003C\u002Fh4>\u003Cp>Obtain the dump file of the lsass process via procdump.exe\u003C\u002Fp>\u003Cp>Requires adding the parameter: -O procdump_path=procdump.exe\u003C\u002Fp>\u003Ch4>(13) procdump_embedded\u003C\u002Fh4>\u003Cp>Same method as above, no need for procdump.exe as a parameter\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(14) rdrleakdiag\u003C\u002Fh4>\u003Cp>The target system must have the file rdrleakdiag.exe under c:\\windows\\system32\\\u003C\u002Fp>\u003Cp>Systems where it exists by default:\u003C\u002Fp>\u003Cp>Windows 10, 10.0.15063.0\u003C\u002Fp>\u003Cp>Windows 8.1, 6.3.9600.17415\u003C\u002Fp>\u003Cp>Windows 8, 6.2.9200.16384\u003C\u002Fp>\u003Cp>Windows 7, 6.1.7600.16385\u003C\u002Fp>\u003Cp>Windows Vista, 6.0.6001.18000\u003C\u002Fp>\u003Cp>Can only be executed once; a system restart is required to execute again\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(15)wer\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FOut-Minidump.ps1\u003C\u002Fp>\u003Cp>Obtain a dump file of the lsass process by calling the API MiniDumpWriteDump() via PowerShell\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch2>0.04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the approach to remotely export credentials from the lsass.exe process, detailing each export method used by Lsassy and analyzing the technical specifics.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Penetration Basics - Extracting Credentials from the lsass.exe Process', methods for locally extracting credentials were introduced. However, in penetration testing, it is often necessary to extract credentials remotely. This article will discuss the concepts and methods for remote credential extraction, detailing the specifics.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Concepts\u003C\u002Fli>\u003Cli>Implementation Methods\u003C\u002Fli>\u003Cli>Introduction to lsassy\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When extracting credentials remotely, the following points need to be considered:\u003C\u002Fp>\u003Cp>(1) Remote command execution must be achieved. For remote command execution, refer to the previous article 'Techniques for Executing Programs on Remote Systems'.\u003C\u002Fp>\u003Cp>(2) Due to protective measures, different environments require different extraction methods.\u003C\u002Fp>\u003Cp>(3) After remotely exporting the dump file of the lsass process, it is common to copy the dump file locally to parse and obtain password hashes. Sometimes, the lsass process dump file is large, so the efficiency of file transfer needs to be considered.\u003C\u002Fp>\u003Cp>(4) For multiple systems, repetitive tasks are too frequent, resulting in low efficiency.\u003C\u002Fp>\u003Cp>Considering the above points, we need a convenient and quick method: support multiple export methods, directly parse password hashes, and automate operations to improve efficiency.\u003C\u002Fp>\u003Cp>The open-source tool Lsassy can be used here, available at: https:\u002F\u002Fgithub.com\u002FHackndo\u002Flsassy\u003C\u002Fp>\u003Ch2>0x03 Introduction to Lsassy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Installation and Usage\u003C\u002Fh3>\u003Cp>Installation command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pip install lsassy\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsassy -u Administrator -p Password1 192.168.1.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the output, colors are added using termcolor. By default, Windows cmd cannot display colors properly, leading to unfriendly formatting and some garbled characters.\u003C\u002Fp>\u003Cp>To solve the formatting issue on Windows, modify \u003Cpython>\\lib\\site-packages\\lsassy\\logger.py with the following code:\u003C\u002Fpython>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import logging\u003Cbr>import os\u003Cbr>import sys\u003Cbr>class LsassyFormatter(logging.Formatter):\u003Cbr>    def __init__(self):\u003Cbr>        logging.Formatter.__init__(self, '%(bullet)s %(threadName)s %(message)s', None)\u003Cbr>        if os.name == 'nt':\u003Cbr>            self.BLUE, self.WHITE, self.YELLOW, self.RED, self.NC = '', '', '', '', ''\u003Cbr>        else:\u003Cbr>            self.BLUE = '\\033[1;34m'\u003Cbr>            self.WHITE = '\\033[1;37m'\u003Cbr>            self.YELLOW = '\\033[1;33m'\u003Cbr>            self.RED = '\\033[1;31m'\u003Cbr>            self.GREEN = '\\033[1;32m'\u003Cbr>            self.NC = '\\033[0m'\u003Cbr>    def format(self, record):\u003Cbr>        if record.levelno == logging.INFO:\u003Cbr>            record.bullet = '[*]{}'.format(self.NC)\u003Cbr>        elif record.levelno == logging.DEBUG:\u003Cbr>            record.bullet = '[*]{}'.format(self.NC)\u003Cbr>        elif record.levelno == logging.WARNING:\u003Cbr>            record.bullet = '[!]{}'.format(self.NC)\u003Cbr>        elif record.levelno == logging.ERROR:\u003Cbr>            record.bullet = '[x]{}'.format(self.NC)\u003Cbr>        else:\u003Cbr>            record.bullet = '[+]{}'.format(self.NC)\u003Cbr>        if record.exc_info and logging.getLogger().getEffectiveLevel() != logging.DEBUG:\u003Cbr>            record.exc_info = None\u003Cbr>        return logging.Formatter.format(self, record)\u003Cbr>def highlight(msg):\u003Cbr>    return msg\u003Cbr>def init(quiet=False):\u003Cbr>    handler = logging.StreamHandler(sys.stdout)\u003Cbr>    handler.setFormatter(LsassyFormatter())\u003Cbr>    logging.getLogger().addHandler(handler)\u003Cbr>    logging.getLogger().setLevel(logging.INFO)\u003Cbr>    logging.addLevelName(25, 'SUCCESS')\u003Cbr>    setattr(logging, 'success', lambda message, *args: logging.getLogger()._log(25, message, args))\u003Cbr>    logging.getLogger().disabled = quiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Package into exe\u003C\u002Fh3>\u003Cp>PyInstaller can be used here, the main program code is at https:\u002F\u002Fgithub.com\u002FHackndo\u002Flsassy\u002Fblob\u002Fmaster\u002Flsassy\u002Fconsole.py\u003C\u002Fp>\u003Cp>Command to package into a standalone exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyinstaller -F console.py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After generating console.exe, an error will be reported during execution indicating missing modules\u003C\u002Fp>\u003Cp>Modify the packaging command based on the output prompts, adding referenced modules:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyinstaller -F console.py --hidden-import unicrypto.backends.pure.DES --hidden-import unicrypto.backends.pure.TDES --hidden-import unicrypto.backends.pure.AES --hidden-import unicrypto.backends.pure.RC4\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>At this point, although console.exe can start normally, the export function cannot run\u003C\u002Fp>\u003Cp>Debugging method: Add the parameter -vv to see that lsassy.dumpmethod.comsvcs cannot be found\u003C\u002Fp>\u003Cp>Add all dependency packages to get the complete packaging command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pyinstaller -F console.py --hidden-import unicrypto.backends.pure.DES --hidden-import unicrypto.backends.pure.TDES --hidden-import unicrypto.backends.pure.AES --hidden-import unicrypto.backends.pure.RC4 --hidden-import lsassy.dumpmethod.comsvcs --hidden-import lsassy.dumpmethod.comsvcs_stealth --hidden-import lsassy.dumpmethod.dllinject --hidden-import lsassy.dumpmethod.dumpert --hidden-import lsassy.dumpmethod.dumpertdll --hidden-import lsassy.dumpmethod.edrsandblast --hidden-import lsassy.dumpmethod.mirrordump --hidden-import lsassy.dumpmethod.mirrordump_embedded --hidden-import lsassy.dumpmethod.nanodump --hidden-import lsassy.dumpmethod.ppldump --hidden-import lsassy.dumpmethod.ppldump_embedded --hidden-import lsassy.dumpmethod.procdump --hidden-import lsassy.dumpmethod.procdump_embedded --hidden-import lsassy.dumpmethod.rdrleakdiag --hidden-import lsassy.dumpmethod.wer --hidden-import lsassy.exec.mmc --hidden-import lsassy.exec.smb --hidden-import lsassy.exec.smb_stealth --hidden-import lsassy.exec.task --hidden-import lsassy.exec.wmi --hidden-import lsassy.output.grep_output --hidden-import lsassy.output.json_output --hidden-import lsassy.output.pretty_output --hidden-import lsassy.output.table_output\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The generated console.exe can now be used normally\u003C\u002Fp>\u003Ch3>3. Supported export methods\u003C\u002Fh3>\u003Ch4>(1) comsvcs\u003C\u002Fh4>\u003Cp>Use the export function MiniDump() from C:\\windows\\system32\\comsvcs.dll to obtain a dump file of the lsass process\u003C\u002Fp>\u003Cp>For details, refer to the previous article \"MiniDumpWriteDump via COM+ Services DLL\" for exploitation testing\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(2) comsvcs_stealth\u003C\u002Fh4>\u003Cp>Similar to comsvcs, the difference is to first copy C:\\windows\\system32\\comsvcs.dll to c:\\windows\\temp and rename it, then use the new dll to obtain a dump file of the lsass process\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(3) dllinject\u003C\u002Fh4>\u003Cp>Implemented through DLL injection\u003C\u002Fp>\u003Cp>For the APC injection method, refer to \"DLL Injection via APC—Bypassing Sysmon Monitoring\"\u003C\u002Fp>\u003Cp>Required parameter: -O loader_path=loader.exe,dll_path=inject.dll\u003C\u002Fp>\u003Ch4>(4) dumpert\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002Foutflanknl\u002FDumpert\u003C\u002Fp>\u003Cp>Obtain dump file of lsass process via API MiniDumpWriteDump()\u003C\u002Fp>\u003Cp>Required parameter: -O dumpert_path=dumpert.exe\u003C\u002Fp>\u003Ch4>(5) dumpertdll\u003C\u002Fh4>\u003Cp>Same method as above, difference is using dll file as parameter\u003C\u002Fp>\u003Cp>Required parameter: -O dumpertdll_path=dumpert.dll\u003C\u002Fp>\u003Ch4>(6) edrsandblast\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002Fwavestone-cdt\u002FEDRSandblast\u003C\u002Fp>\u003Cp>Obtain lsass process dump file using signed driver\u003C\u002Fp>\u003Cp>Required parameter: -O edrsandblast_path=EDRSandBlast.exe,RTCore64_path=RTCore64.sys,ntoskrnl_path=NtoskrnlOffsets.csv\u003C\u002Fp>\u003Ch4>(7) mirrordump\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002FCCob\u002FMirrorDump\u003C\u002Fp>\u003Cp>Implementation process:\u003C\u002Fp>\u003Cul>\u003Cli>Load an LSA SSP plugin\u003C\u002Fli>\u003Cli>Leak the process handle of lsass.exe within the plugin\u003C\u002Fli>\u003Cli>Obtain the dump file of the lsass process via the API MiniDumpWriteDump()\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Requires adding the parameter: -O mirrordump_path=Mirrordump.exe\u003C\u002Fp>\u003Ch4>(8) mirrordump_embedded\u003C\u002Fh4>\u003Cp>Method is the same as above, Mirrordump.exe is not required as a parameter\u003C\u002Fp>\u003Cp>Note that mirrordump cannot automatically clear the registered LSA SSP plugin; using this method will leave the following traces:\u003C\u002Fp>\u003Cul>\u003Cli>The LSA SSP plugin is saved in C:\\Windows\\System32, with an eight-character random name and a .dll extension\u003C\u002Fli>\u003Cli>Residual unloaded dll in the lsass process\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Traces are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017249815_0_b461d80d2e-1.jpeg\">\u003C\u002Fp>\u003Cp>Method to clear traces: first unload the dll loaded in the lsass process, then delete the dll file\u003C\u002Fp>\u003Cp>For details on enumerating and clearing LSA SSP plugins, refer to the previous article 'Usage of SSP in Mimikatz'\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(9) nanodump\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002Fhelpsystems\u002Fnanodump\u003C\u002Fp>\u003Cp>Advantage: supports multiple methods to leak lsass process handles\u003C\u002Fp>\u003Cp>Required parameter: -O nanodump_path=nanodump.exe\u003C\u002Fp>\u003Ch4>(10) ppldump\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002Fitm4n\u002FPPLdump\u003C\u002Fp>\u003Cp>Supports Windows 10 and Server 2019\u003C\u002Fp>\u003Cp>Can bypass PPL (Protected Process Light) protection for lsass process\u003C\u002Fp>\u003Cp>Related details:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fitm4n.github.io\u002Flsass-runasppl\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.scrt.ch\u002F2021\u002F04\u002F22\u002Fbypassing-lsa-protection-in-userland\u002F\u003C\u002Fp>\u003Cp>Required parameter: -O ppldump_path=PPLdump.exe\u003C\u002Fp>\u003Ch4>(11) ppldump_embedded\u003C\u002Fh4>\u003Cp>Same method as above, does not require PPLdump.exe as parameter\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(12) procdump\u003C\u002Fh4>\u003Cp>Obtain the dump file of the lsass process via procdump.exe\u003C\u002Fp>\u003Cp>Requires adding the parameter: -O procdump_path=procdump.exe\u003C\u002Fp>\u003Ch4>(13) procdump_embedded\u003C\u002Fh4>\u003Cp>Same method as above, no need for procdump.exe as a parameter\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(14) rdrleakdiag\u003C\u002Fh4>\u003Cp>The target system must have the file rdrleakdiag.exe under c:\\windows\\system32\\\u003C\u002Fp>\u003Cp>Systems where it exists by default:\u003C\u002Fp>\u003Cp>Windows 10, 10.0.15063.0\u003C\u002Fp>\u003Cp>Windows 8.1, 6.3.9600.17415\u003C\u002Fp>\u003Cp>Windows 8, 6.2.9200.16384\u003C\u002Fp>\u003Cp>Windows 7, 6.1.7600.16385\u003C\u002Fp>\u003Cp>Windows Vista, 6.0.6001.18000\u003C\u002Fp>\u003Cp>Can only be executed once; a system restart is required to execute again\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch4>(15)wer\u003C\u002Fh4>\u003Cp>Technical details: https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FOut-Minidump.ps1\u003C\u002Fp>\u003Cp>Obtain a dump file of the lsass process by calling the API MiniDumpWriteDump() via PowerShell\u003C\u002Fp>\u003Cp>Can be used directly\u003C\u002Fp>\u003Ch2>0.04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the approach to remotely export credentials from the lsass.exe process, detailing each export method used by Lsassy and analyzing the technical specifics.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",753,"Onedaysec",5,"published","2026-02-02T07:38:21.198Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Remote Credential Extraction from lsass.exe Process - Penetration Testing Basics","lsass.exe, remote credential extraction, penetration testing, lsassy tool, password hashes, dump file, Windows security",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],821,820,818,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.374Z","2026-07-23T16:02:08.503Z","draft","2026-07-23T16:14:56.357Z"]