Skip to content
← LibraryTechnique entry
W-LSASS-PROCDUMPCredential Access

LSASS via procdump / comsvcs.dll

rundll32.exe C:\windows\system32\comsvcs.dll MiniDump <pid> dump.dmp full — dump LSASS without Mimikatz signature.

§ Where this technique fits

W-LSASS-PROCDUMP is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 9 approved dossiers in the registry, typically at step 4.8 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    AdminSDHolder Abuse
    AD-ADMINSDHOLDER · Persistence
    seen 2×
  2. 02
    Pass the Hash
    T1550.002 · Lateral Movement
    seen 2×
  3. 03
    SMB/Windows Admin Shares
    T1021.002 · Lateral Movement
    seen 1×