Environment
- Endpoint Standard Sensor 3.5.0.1523 and higher
- Microsoft Windows: All Supported Versions
Question
What type of memory dump is generated in a Live Response session?
Answer
The memory dump generated over a Live Response session quickly collects a kernel memory dump (and user space, if kernel debugging is enabled).
For example, the command below will create a dump in c:\temp:
memdump c:\temp\kernel.dmp
Additional Notes
If a full memory dump is required, follow the instructions
here, please note a reboot will be required.
Related Content