vari-sh.bsky.social
@vari-sh.bsky.social
Reposted
Just read this amazing article about #processinjection technique #doppelganger

This one here gives a detailed and understandable inside of this technique for #redteam and #blueteam equally.

vari-sh.github.io/posts/doppel...
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Technique for cloning and dumping LSASS to evade detection using RTCore64.sys, NtCreateProcessEx and MiniDumpWriteDump.
vari-sh.github.io
April 14, 2025 at 1:58 PM
Reposted
Doppelganger : Cloning and Dumping LSASS to Evade Detection using RTCore64.sys, NtCreateProcessEx and MiniDumpWriteDump : vari-sh.github.io/posts/doppel...
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Technique for cloning and dumping LSASS to evade detection using RTCore64.sys, NtCreateProcessEx and MiniDumpWriteDump.
vari-sh.github.io
April 24, 2025 at 3:48 PM
Reposted
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Doppelganger: Cloning and Dumping LSASS to Evade Detection
vari-sh.github.io
April 11, 2025 at 7:54 PM
Reposted
Doppelganger: Cloning and Dumping LSASS to Evade Detection
Doppelganger: Cloning and Dumping LSASS to Evade Detection
vari-sh.github.io
April 13, 2025 at 3:09 PM
Reposted
Security researcher Vari[.]sh has published details on Doppelganger, a new technique (and tool) designed to clone LSASS and extract secrets from the clone process without triggering detections on the original

vari-sh.github.io/posts/doppel...

POC: github.com/vari-sh/RedT...
April 13, 2025 at 2:34 PM