Uncensored AI Model Creates LSASS Credential Dumper That Bypasses EDR Detection
Brief
A new demonstration shows how an uncensored, locally hosted AI model can generate a functional LSASS credential-dumping tool that reportedly avoided detection by two endpoint detection and response platforms in a controlled lab.
The result highlights how low-cost, guardrail-free models could reduce the time and expertise needed to develop malware-like post-exploitation tooling.
According to research published by Project Black’s Eddie Zhang on September 24, the experiment examined whether AI could produce an executable that dumps the Windows Local Security Authority Subsystem Service (LSASS) process while evading modern EDR controls.
