Dumpert is a Windows credential-dumping utility focused on extracting LSASS memory while evading user-mode security monitoring. Publicly associated with Outflank and originally released in 2019 as a proof of concept, it is designed to bypass userland API hooks used by AV and EDR products by invoking direct Windows system calls and using API unhooking techniques rather than relying on standard hooked user-mode functions. This tradecraft is intended to reduce visibility during LSASS access and memory dumping operations.
The tool is used for OS credential dumping from lsass.exe and is commonly discussed alongside Mimikatz and ProcDump as an alternative approach for credential access. Its core behavior centers on dumping LSASS memory through direct syscalls, making it relevant to defenses focused on T1003.001-style credential theft. Dumpert has also been referenced in broader discussions of EDR bypass methods because it embeds or leverages syscall logic to avoid normal monitored API paths.
Dumpert targets 64-bit Windows environments. It has been observed or cited in intrusion reporting as a dual-use utility employed by threat actors during post-compromise credential access, including reporting tied to intrusions against government environments and to DPRK-linked Andariel activity. It has also been referenced in relation to Chimera tradecraft and Skeleton Key-related operations as an example of direct-syscall-based credential dumping. High-confidence reporting supports its role as a specialized LSASS dumping tool rather than a general-purpose remote access implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Chimera added extracted key code snippets from both Mimikatz and Dumpert to their customized Skeleton Key.
The actors employ... credential theft utilities and dual-use tools such as Mimikatz, Dumpert, and ProcDump...
5 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used to dump LSASS process memory to obtain credentials; often used alongside injection/evasion tradecraft to access protected processes.
Dumpert is referenced as a source of code snippets incorporated into a customized Skeleton Key used by APT Chimera to bypass API monitoring and support credential-access-related operations.
LSASS memory dumping tool that uses direct system calls and API unhooking to evade user-mode security hooks while obtaining credential material from LSASS.
A tool demonstrating direct system calls to bypass userland hooking, primarily discussed as an example of EDR evasion and LSASS dumping tradecraft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.