Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

CB Response: Live Response - Error Getting Memdump: Remote Error HRESULT 0x8000ffff

CB Response: Live Response - Error Getting Memdump: Remote Error HRESULT 0x8000ffff

Environment

  • CB Response Server: 5.1.1 and Higher

Symptoms

Error message seen when trying to create a memory dump through live response:
Error getting memdump: Remote error HRESULT 0x8000ffff

Cause

If the folder is non-existent, or a file name is not being specified, the memory dump will not create.

Resolution

Specify the folder path and name of the file when running the memdump command.

Additional Notes

  • When memdump command run in a directory that is known to exist on the endpoint, there will be a spinning icon acknowledging that the server has made the call and is waiting for the memory dump to be sent up. Once it is complete, the Live Response page will give a pop-up to download and save the file locally.
  • Live Response can be used to create a folder in a specific directory, using the "mkdir" command.
  • Memdumps cannot be created directly to a remote IP - they must be created locally on the endpoint with Live Response.

Related Content


Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎03-11-2019
Views:
1090
Contributors