Posts

Showing posts with the label rdrleakdiag

304. Adversaries Abuse Microsoft Windows Resource Leak Diagnostic Tool for Dumping Memory

Image
Hello everyone! It's not always LSASS, in some cases adversaries may create full memory dumps and use it for accessing credentials. In this case , the adversary leveraged Microsoft Windows Resource Leak Diagnostic tool to obtain a memory dump: rdrleakdiag /p [REMOVED] /o CSIDL_PROFILE\downloads /fullmemdmp /wait 1 Let's build a query: event_type: "processcreatewin" AND proc_file_path: "rdrleakdiag.exe" AND cmdline: "fullmemdmp" See you tomorrow!