February 2018
Intermediate to advanced
396 pages
9h 38m
English
Memory dumping is a classic technique to recover some hidden information, including passwords and credentials. One of the Active Directory techniques is dumping LSASS memory using the Task Manager. Mimikatz has great capabilities, such as the features discussed before; one of them is dumping LSASS memory from the LSASS.dmp file, as shown:

If the operation succeeds, you will receive this message:
