Dump Credential Access Windows Creates a memory dump of the LSASS process. Use Create memory dump and parse it offline to retrieve credentials. dump64.exe {PID} out.dmp copy Contextadmin NativeDump MITRET1003.001 DetectionSigma: github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_dump64.ymlIOC: As a Windows SDK binary, execution on a system may be suspicious Refstwitter.com/mrd0x/status/1460597833917251595lolbas-project.github.io/lolbas/OtherMSBinaries/Dump64/