discovered 17 Aug 2026
TrickDump
→ View on GitHubTrickDump is a tool designed for stealthily dumping the lsass process without generating a Minidump file, instead creating three JSON files and one ZIP file containing memory region dumps. Its primary use case is for bypassing conventional monitoring by executing three separate programs—Lock, Shock, and Barrel—that leverage NTAPIs for memory access, while offering various execution methods including different programming languages and techniques for API hook evasion. Notably, TrickDump allows for targeted execution without exposing process handles, enhancing its stealth capabilities against common antivirus and endpoint detection solutions.