Python library to parse remote lsass dumps
Python library to remotely extract credentials on a set of hosts. This blog post explains how it works.
|Requirements||Requirements to install lsassy from source|
|Warning||Before using this tool, read this|
|CrackMapExec Module||Link to CrackMapExec module included in this repository|
|Issues||Read this before creating an issue|
|Acknowledgments||Kudos to these people and tools|
|Official Discord||Official Discord channel|
- Python >= 3.6
Although I have made every effort to make the tool stable, traces may be left if errors occur.
This tool can either leave some lsass dumps if it failed to delete it (eventhough it tries hard to do so) or leave a scheduled task running if it fails to delete it. This shouldn't happen, but it might. Now, you know, use it with caution.
The tool is fully documented in the project's wiki
- CrackMapExec module is now part of CrackMapExec project
- CME module is documentated in project's wiki
v2.1.0 ------ * Kerberos authentication support (Thank you laxa for PR) * Add CME module for python3 * Update bloodhound queries for BloodHound3 * Bug fixes v2.0.0 ------ * Multiprocessing support to dump credentials on multiple hosts at a time * Add new dumping method using "dumpert" * Can be used as a library in other python projects * Syntax changed to be more flexible * Complete code refactoring, way more organized and easy to maintain/extend * Better error handling * Complete wiki v1.1.0 ------ * Better execution process : --method flag has been added and described in help text * Uses random dump name * Chose between cmd, powershell, dll and/or procdump methods * CME module is now using light lsassy WMIExec et TASKExec implementation * Bug fixes v1.0.0 ------ * Built-in lsass dump ** Lsass dump using built-in Windows ** Lsass dump using procdump (using -p parameter) * Add --dumppath to ask for remote parsing only * Code refactoring * Add --quiet to quiet output v0.2.0 ------ * Add BloodHound option to CME module (-o BLOODHOUND=True) - Set compromised targets as "owned" in BloodHound - Check if compromised users have at least one path to domain admin * Custom parsing (json, grep, pretty [default]) * New --hashes option to lsassy * Include CME module in repository * Add credentials to CME database v0.1.0 ------ First release
Official Discord Channel
Release history Release notifications | RSS feed
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
|Filename, size||File type||Python version||Upload date||Hashes|
|Filename, size lsassy-2.1.5-py3-none-any.whl (25.4 kB)||File type Wheel||Python version py3||Upload date||Hashes View|
|Filename, size lsassy-2.1.5.tar.gz (20.6 kB)||File type Source||Python version None||Upload date||Hashes View|