A new demonstration showcases how an uncensored, locally hosted AI model can create a functional LSASS credential-dumping tool, reportedly evading two endpoint detection and response platforms in a controlled lab setting This article explores ai produce executable. . According to research by Project Black’s Eddie Zhang on September 24, the experiment tested whether AI could produce an executable that dumps the Windows Local Security Authority Subsystem Service (LSASS) process while evading modern EDR controls.
These changes aimed to alter process spawning behavior, minimize requested access permissions for the target process, introduce timing delays during dump creation, modify the output file's name and location, and obscure embedded strings in the executable.
While the research does not confirm that every EDR platform can be bypassed or that the technique will remain effective across environments, EDR detections can vary significantly based on product, configuration, telemetry collection, behavioral rules, Windows protections, and response policies. By limiting local administrative rights, enabling Windows credential protections like Credential Guard, restricting debugging privileges, monitoring suspicious access to LSASS, and maintaining strong segmentation and privileged-access controls, defenders can mitigate the impact of LSASS-focused activities. Project Black highlighted that inexpensive rented compute or local GPU hardware can make custom evasion development much more accessible, emphasizing the importance of credential hygiene and least-privilege enforcement.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort.










.webp)