#progs_dump search results

I developed a small @PhpStorm plugin that displays dump/dd output. It's similar to Ray from Spatie or Symfony's Dump Server, but shows dumps inside the IDE. Does this seem useful to you? Should I release it?

pronskiy's tweet image. I developed a small @PhpStorm plugin that displays dump/dd output. 

It's similar to Ray from Spatie or Symfony's Dump Server, but shows dumps inside the IDE. 

Does this seem useful to you? Should I release it?

Today we're diving into Linux internals - figuring out how to dump memory from another process! We talk about the why the /proc filesystem is so cool, as well as the ptrace system call, and end up building our own program to peek into private processes! youtube.com/watch?v=0ihChI…

lowbyteprod's tweet image. Today we're diving into Linux internals - figuring out how to dump memory from another process!

We talk about the why the /proc filesystem is so cool, as well as the ptrace system call, and end up building our own program to peek into private processes!

youtube.com/watch?v=0ihChI…

Great blog by @ShitSecure about LSASS dumping but also some good examples on how to solve some PE loading from memory issues, take a look: s3cur3th1ssh1t.github.io/Reflective-Dum…


One funny way to use procdump to dump lsass and not get flagged by defender is to redirect it to smb share where only current user can authenticate (you can use dummy user with runas /netonly). Defender will not be able to scan dump file and will not flag it.

filip_dragovic's tweet image. One funny way to use procdump to dump lsass and not get  flagged by defender is to redirect it to smb share where only current user can authenticate (you can use dummy user with runas /netonly). Defender will not be able to scan dump file and will not flag it.
filip_dragovic's tweet image. One funny way to use procdump to dump lsass and not get  flagged by defender is to redirect it to smb share where only current user can authenticate (you can use dummy user with runas /netonly). Defender will not be able to scan dump file and will not flag it.
filip_dragovic's tweet image. One funny way to use procdump to dump lsass and not get  flagged by defender is to redirect it to smb share where only current user can authenticate (you can use dummy user with runas /netonly). Defender will not be able to scan dump file and will not flag it.

We’re all familiar with the function `print()`… …but have you ever hard of `dump()`? 🤨 `dump()` is really useful when working with classes! Let me show you an example 🔥


#HuntingTipOfTheDay You know procdump can be used to dump passwords. Do you know about #PowerShell and WindowsErrorReporting?🧐 github.com/PowerShellMafi… 🙏@mattifestation #NotNewButStillInUse

JohnLaTwC's tweet image. #HuntingTipOfTheDay 
You know procdump can be used to dump passwords.  Do you know about #PowerShell and WindowsErrorReporting?🧐

github.com/PowerShellMafi…
🙏@mattifestation #NotNewButStillInUse

Oh wow ProcDump can wait until a process reaches a certain CPU threshold before it creates a dump, and it can do this several times. Interesting way to get diagnostic dumps of server applications misbehaving randomly.


I recently found out I really like to break software protectors. So, here's a mini-project I've been working on for the last week or so: VMPDump, an open-source, well-documented VMProtect dumper and import fixer. No more broken dumps! github.com/0xnobody/vmpdu…

github.com

GitHub - 0xnobody/vmpdump: A dynamic VMP dumper and import fixer, powered by VTIL.

A dynamic VMP dumper and import fixer, powered by VTIL. - 0xnobody/vmpdump


Yet another process dump method: rdrleakdiag.exe /p <pid> /o <outputdir> /fullmemdmp /wait 1


Procdump alternative that may come handy during #redteam github.com/Mr-Un1k0d3r/Mi… There is a C and a C# version that can be used with execute-assembly ❤


Sigma rule to detect ProcDump use on LSASS > often used to dump process memory, transfer it to attacker controlled system & use the password dumper there w/o the risk of detection Rule github.com/Neo23x0/sigma/… Background blog.gentilkiwi.com/securite/mimik…

cyb3rops's tweet image. Sigma rule to detect ProcDump use on LSASS
&amp;gt; often used to dump process memory, transfer it to attacker controlled system &amp;amp; use the password dumper there w/o the risk of detection 
Rule
github.com/Neo23x0/sigma/…
Background
blog.gentilkiwi.com/securite/mimik…
cyb3rops's tweet image. Sigma rule to detect ProcDump use on LSASS
&amp;gt; often used to dump process memory, transfer it to attacker controlled system &amp;amp; use the password dumper there w/o the risk of detection 
Rule
github.com/Neo23x0/sigma/…
Background
blog.gentilkiwi.com/securite/mimik…
cyb3rops's tweet image. Sigma rule to detect ProcDump use on LSASS
&amp;gt; often used to dump process memory, transfer it to attacker controlled system &amp;amp; use the password dumper there w/o the risk of detection 
Rule
github.com/Neo23x0/sigma/…
Background
blog.gentilkiwi.com/securite/mimik…

Interesting alternative for #RedTeam, #ThreatActors to dump LSASS. Use #MSFT legitimate binary Sqldumper.exe instead of Procdump. #DFIR

countuponsec's tweet image. Interesting alternative for #RedTeam, #ThreatActors to dump LSASS. Use #MSFT legitimate binary Sqldumper.exe instead of Procdump. #DFIR

No results for "#progs_dump"
No results for "#progs_dump"
Loading...

Something went wrong.


Something went wrong.


United States Trends