discovered 03 Aug 2026
HashDump-BypassEDR
→ View on GitHubHashDump-BypassEDR is a tool designed to circumvent Endpoint Detection and Response (EDR) solutions by utilizing the `reg.exe` command to export critical registry information, enabling the dumping of password hashes from Windows systems. Its notable features include the ability to operate with minimal permissions on certain Windows versions, alongside an effective method for retrieving the BootKey necessary for the process without detection by most antivirus software. The tool's practicality is underscored by its testing across various Windows environments, showcasing its robustness in real-world applications.