Local AI model revised LSASS dumper that evaded lab EDRs
Eddie Zhang said a local uncensored Qwen model revised an LSASS dumper until two unnamed lab EDRs stopped alerting.
Eddie Zhang of Project Black reported on 26 September 2026 that hosted Claude models refused to build a Windows LSASS credential dumper, while DeepSeek v4 Flash produced an initial dump that EDR detected. Cyber Security News identifies that model as DeepSeek v4 Flash 0731 and says it then applied a safety guardrail, a detail GBHackers does not state. A locally hosted uncensored Qwen derivative—named Qwen3.8-27B by GBHackers and Qwen 3.8 27B by Cyber Security News, and run on dual RTX 4090s according to GBHackers—revised the tool after a request for greater stealth. GBHackers says those revisions changed process behavior, access rights, timing, paths, and strings, and that the resulting dump parsed with pypykatz. In the lab, the revised binary reportedly produced no alerts from two unnamed EDR products. Both outlets say vendors and configurations were unpublished, so the finding is a point-in-time lab observation rather than a confirmed universal bypass; Cyber Security News also cites Microsoft’s LSASS Attack Surface Reduction, Protected Process Light, and Credential Guard.
- On 2026-09-26, Eddie Zhang of Project Black reported lab tests of AI-built Windows LSASS credential dumpers.
- Hosted Claude models refused the task.
- DeepSeek v4 Flash (Cyber Security News specifies the 0731 release) produced an initial dump that EDR detected; that outlet also says DeepSeek then applied a safety guardrail.
- A locally hosted uncensored Qwen model—Qwen3.8-27B in GBHackers, Qwen 3.8 27B in Cyber Security News—revised the dumper; GBHackers says it ran on dual RTX 4090s.
- GBHackers says revisions changed process behavior, access rights, timing, paths, and strings, and that the dump parsed with pypykatz.
- The revised binary reportedly generated no alerts from two unnamed lab EDR products; vendors and configurations were not published.
- Both sources call the result a point-in-time lab observation, not a confirmed universal EDR bypass.
- Cyber Security News cites Microsoft defenses: LSASS Attack Surface Reduction, Protected Process Light, and Credential Guard.
Coverage timelineoldest first · each row is one article
- · 1d agoUncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials
GBHackers· 62
An uncensored local Qwen derivative generated an LSASS dumper that evaded two EDRs in lab tests.
- · 16h agoLocal AI Model Modifies Windows Credential Dumper to Bypass EDR Detection
Cyber Security News· 64
A local uncensored Qwen model revised an LSASS dumper until two lab EDRs no longer detected it.