Skip to content

Modules that interact with LSASS should allow for manually inputting the PID #1091

@sugoiaoi

Description

@sugoiaoi

The SMB modules that interact with LSASS should allow you to supply the PID of the LSASS process. I have frequently experienced issues with running lsassy and nanodump, where once it issues the tasklist/findstr combo looking for lsass, it gets flagged. I have always been able to determine the LSASS PID in other ways, so it would be nice to be able to supply it as a module option in the hopes of getting through defenses.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions