Package rekall :: Package plugins :: Package windows :: Package registry :: Module lsadump
[frames] | no frames]

Module lsadump

source code


Author: AAron Walters and Brendan Dolan-Gavitt

License: GNU General Public License 2.0 or later

Contact: awalters@volatilesystems.com,bdolangavitt@wesleyan.edu

Organization: Volatile Systems

Classes
  LSADump
Dump (decrypted) LSA secrets from the registry
  HashDump
Dumps passwords hashes (LM/NTLM) from memory