Dumping LSASS.exe
Dumping LSASS without mimikatz
Procdump
Procdump is a Microsoft signed administration tool, not typically flagged.
Comsvcs.dll
Can be wrapped in a powershell command too:
ProcessDump.exe from Cisco Jabber
Cisco Jabber comes with a binary called ProcessDump.exe which can be used like procdump.
Location: C:\Program Files (x86)\Cisco Systems\Cisco Jabber\x64\ProcessDump.exe
Task Manager
Requires graphical access in addition to administrator rights.
Last updated
Was this helpful?