Hello there,
First of all, I wanna thank you for this awesome tool . I love the idea, and it works 90% of the time, life saver. Great research.
And because it is awesome, I was thinking about a way to dump lsass locally using this tool. Since the physical memory is exposed as a file over TCP, I guess it wouldn't be that difficult to have a client in C# that would locally connect to the server and dump lsass on the target disk.
This way, there would be a single tool that would
- expose RAM on 127.0.0.1:<port>
- connect to that local port and dump lsass directly on the host
Do you think it is possible (theoretically) or am I missing something?
I'm not asking you to actually develop this, it's more of a thought sharing process, is it possible, is there something I forgot, what do you think about it,...
Again, thank you!