ATPMiniDump icon indicating copy to clipboard operation
ATPMiniDump copied to clipboard

Evading WinDefender ATP credential-theft

ATPMiniDump

Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis