-
Notifications
You must be signed in to change notification settings - Fork 439
4.5. Create a MiniDump of the full process (minidmp)
hasherezade edited this page Dec 28, 2021
·
4 revisions
By default, PE-sieve extracts and dumps the elements that are detected as potential implants (PEs, and optionally shellcodes). However, sometimes you may like to make a dump of the full process space.
When the option /minidmp
is chosen, PE-sieve will create a minidump of the full process that was detected as suspicious (in addition to dumping the implants).