Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Convert lsass dump from a vmem memory snapshot to dmp #798

Open
5433D-R32433 opened this issue Jun 17, 2021 · 0 comments
Open

Convert lsass dump from a vmem memory snapshot to dmp #798

5433D-R32433 opened this issue Jun 17, 2021 · 0 comments

Comments

@5433D-R32433
Copy link

5433D-R32433 commented Jun 17, 2021

I get memdump and procdump from lsass in a vmem snapshot file( I have snapshot and suspend files of vmware virtual machines: vmsn, vmss, vmem ). but I can not open it with windbg or mimikatz. I tried to convert the raw memory dump to dmp with volatility but it failed( through raw2dmp and through a couple of other tools ).
what's the format of memdump files and how we can convert them to Windows dump format. as I know the procdump command get the PE file of the executable process from memory. how can we convert them to dmp.

thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant