Tttracer.exe

Used by Windows 1809 and newer to Debug Time Travel

Paths

  • C:\Windows\System32\tttracer.exe
  • C:\Windows\SysWOW64\tttracer.exe

Commands

Execute

Execute specified executable from tttracer.exe. Requires administrator privileges.

Use case: Spawn process using other binary

Privileges: Administrator

tttracer.exe {PATH_ABSOLUTE:.exe}

Dump

Dumps process using tttracer.exe. Requires administrator privileges

Use case: Dump process by PID

Privileges: Administrator

TTTracer.exe -dumpFull -attach {PID}

Detection

Resources