Title:HackTool - WSASS Execution Status:experimental Description:Detects execution of WSASS, a tool used to dump LSASS memory on Windows systems by leveraging WER's
(Windows Error Reporting) WerFaultSecure.EXE to bypass PPL (Protected Process Light) protections.
References: -https://github.com/TwoSevenOneT/WSASS -https://www.zerosalarium.com/2025/09/Dumping-LSASS-With-WER-On-Modern-Windows-11.html Author: Swachchhanda Shrawan Poudel (Nextron Systems) Date: 2025-11-23 modified:2026-01-09 Tags: