/ATPMiniDump

Evading WinDefender ATP credential-theft

Primary LanguageCBSD 3-Clause "New" or "Revised" LicenseBSD-3-Clause

ATPMiniDump

Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis