fbpx
cybersecurity
education
€ EUR
  • $ USD
  • € EUR

Hacks Weekly #63 – Attacking LSASS memory through VM snapshot

Welcome to another episode of Hacks Weekly! 

In this one, we’ll show you how to dump the LSASS.exe (Local Security Authority Subsystem Service) file using snapshots from the VMware vSphere virtual machine.

Discover how this technique enables attackers to obtain a full memory dump of the LSASS in our video by Cybersecurity Experts Paula Januszkiewicz, Marcin Kozłowski, and CQURE Team.

 

 

By leveraging snapshots, attackers can bypass security mechanisms and extract passwords or access tokens, allowing privilege escalation across the entire network. 


Watch the video above to find out how hackers can lay their hands on passwords by taking a snapshot of the running VM along with the memory and downloading the snapshot memory status files, VMM, and VMSN accelerate.

We hope this demonstration will help you understand how hackers work and how to keep your infrastructure secure from them.

Watch the full video with step-by-step guidance👉

Paula
Januszkiewicz
Founder & CEO, Microsoft Regional Director, MVP, MCT

Paula is a world-class Cybersecurity Expert with over 19 years of experience in the field. She is often a top-rated speaker at the world biggest conferences as her unique stage presence is always well-received among diverse audiences. To top it all, she has the access to the source code of Windows!

All articles by Paula

You may also be interested in:

How can we help you?

Suggested searches

    Search history

      Popular searches:

      Not sure what course to look for?

      Mobile Newsletter Form