LSASS Access
-
OpenProcess(target: lsass.exe) -
MiniDumpWriteDump -
ReadProcessMemory
Token Theft
-
OpenProcessToken -
DuplicateTokenEx -
ImpersonateLoggedOnUser -
SetThreadToken
OpenProcess (target: lsass.exe)
MiniDumpWriteDump
ReadProcessMemory
OpenProcessToken
DuplicateTokenEx
ImpersonateLoggedOnUser
SetThreadToken