DumpMinitool.exe

Dump tool part Visual Studio 2022

Paths

  • C:\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\Extensions\TestPlatform\Extensions\DumpMinitool.exe

Commands

Dump

Creates a memory dump of the lsass process

Use case: Create memory dump and parse it offline

Privileges: Administrator

DumpMinitool.exe --file {PATH_ABSOLUTE} --processId 1132 --dumpType Full

Detection

Resources