Dump File Analysis
Enumeration of memory dumps
LSAS
Pypykatz install
Pypykatz LSAS analysis
Strings and Regex
Last updated
Enumeration of memory dumps
Last updated
git clone https://github.com/skelsec/pypykatz.git
python3 setup.py install pypykatz lsa minidump lsass.DMPstrings ./LogonUI.DMP | egrep -x '.{7,}'strings ./explorer.DMP | egrep -x '.{10,}' | egrep -v "\.lnk|\.cpp|\.dll|xxxx|\.pdb|Font|ENTITY|PADDING|DOS mode|\?\?\?\?"