Dump64.exe

Memory dump tool that comes with Microsoft Visual Studio

Paths

  • C:\Program Files (x86)\Microsoft Visual Studio\Installer\Feedback\dump64.exe

Commands

Dump

Creates a memory dump of the LSASS process.

Use case: Create memory dump and parse it offline to retrieve credentials.

Privileges: Administrator

dump64.exe {PID} out.dmp

Detection

Resources