Lsassy

Latest version: v3.1.13

Safety actively analyzes 723650 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 3 of 4

3.1.0

Features

* Add `--copy` parameter to copy "cmd.exe" or "powershell.exe" to C:\Windows\Temp with a random name before using them for command execution
* Add [EDRSandBlast](https://github.com/wavestone-cdt/EDRSandblast) dump method from [th3m4ks](https://twitter.com/th3m4ks) and [Qazeer](https://twitter.com/_Qazeer) technique. It will upload their executable, and the vulnerable driver to remove EDR kernel callbacks, dump lsass, and restore EDR kernel callbacks.
* Add [nanodump](https://github.com/helpsystems/nanodump) method from [s4ntiago_p](https://twitter.com/s4ntiago_p)
* Add [Rdrleakdiag technique](https://twitter.com/0gtweet/status/1299071304805560321) technique from [0gtweet](https://twitter.com/0gtweet)

Improvements

* Refactor dependencies to make it easier to create new dump modules based on compiled tools
* Possibility to host tools on a SMB server and provide the share path to lsassy
* Automatic listing of dump methods and execution methods in help
* Update `comsvcs_stealth` technique using [cyb3rops](https://twitter.com/cyb3rops) [tweet info](https://twitter.com/cyb3rops/status/1469249058137067520)

3.0.3

Features
* Add MirrorDump (https://github.com/CCob/MirrorDump) thanks to snovvcrash PR (https://github.com/Hackndo/lsassy/pull/62)
* Ability to provide an SMB share for dumpertdll method

Fixes
* Random extension bug when extension is forced by dumping method based on davidmckennirey idea (https://github.com/Hackndo/lsassy/issues/61)
* Issue with ctrl+c not quitting

3.0.0

New version of lsassy, with lots of new feature, based on some awesome work of awesome people <3
* Complete rewrite of the tool
* Way more modular
* Easy way to add new dump method, exec method, output formats
* Add new dump methods
* dumpertdll (https://github.com/outflanknl/Dumpert)
* comsvcs_stealth
* procdump_embedded
* dllinject (advanced)
* ppldump (https://github.com/itm4n/PPLdump)
* ppldump_embedded (https://github.com/itm4n/PPLdump)
* wer (https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Out-Minidump.ps1)
* Add execution methods
* SMB service creation (https://github.com/SecureAuthCorp/impacket)
* SMB service modification (https://raw.githubusercontent.com/Mr-Un1k0d3r/SCShell/master/scshell.py)
* MMC (https://github.com/byt3bl33d3r/CrackMapExec/blob/master/cme/protocols/smb/mmcexec.py)
* Add "parse-only" feature to parse remote existing dump
* Rewrote multithread logic
* Random dump extension by default
* Add binary compilation code

2.1.5

* Changed scheduled task to execute once
* Minor bug fixes

2.1.3

2.1.2

Previous update fixed some output bugs. CME modules were updated accordingly.

Page 3 of 4

© 2025 Safety CLI Cybersecurity Inc. All Rights Reserved.