Skip to content

ricardojoserf/NativeDump

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

19 Commits
 
 
 
 
 
 

Repository files navigation

NativeDump - "ntdlloverwrite" branch

This branch implements Ntdll.dll remapping by overwriting the process library ".text" section with the clean section from the file "C:\Windows\System32\ntdll.dll". You can find more remapping options in SharpNtdllOverwrite.

Usage

NativeDump.exe [DUMP_FILE]
  • DUMP_FILE: Name of file to create. The default file name is "proc_.dmp".

Example

img

About

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Contributors

Languages