Microsoft .NET Runtime Crash Dump Generator (included in .NET Core)
- C:\Program Files\dotnet\shared\Microsoft.NETCore.App\*\createdump.exe
- IOC: createdump.exe process with a command line containing the lsass.exe process id
Dump process by PID and create a minidump file. If "-f dump.dmp" is not specified, the file is created as '%TEMP%\dump.%p.dmp' where %p is the PID of the target process.
Usecase: Dump process memory contents using PID.
createdump.exe -n -f dump.dmp [PID]
Privileges required: SYSTEM
OS: Windows 10, Windows 11
MITRE ATT&CK®: T1003