Open DigiAngel opened 7 years ago
We don't currently have support for minidumps, but I know some people have worked on it in the past. Not sure if they have released any plugins for Volatility yet, however. I know @moyix had released a tool a while back that may prove useful, as well: http://moyix.blogspot.com/2008/05/parsing-windows-minidumps.html
Thanks...ironically I have that .py on my drive :) Hopefully you folks will get this feature in somedays. Sometimes I only get a chance to get the proc dump, not a full memory dump :(
+1 ... I would also be glad seeing this in volatility.
+1 as the minidump is quite common.
The raw2dmp
can create a minidump. But it seems only kernel address space...
Why there is not exists pid or eprocess option for dumping usermode process?
Not sure if this has been asked, but I thought I'd give it a go. I'm hoping for Minidump support in volatility. These are acquired using tools like ProcessHacker or Process Explorer...the file command shows:
and the first bits of hex:
ImageInfo shows:
kpcrscan and kdbgscan come up with nothing. Thank you.