Skip to content

4.5. Create a MiniDump of the full process (minidmp)

hasherezade edited this page Dec 28, 2021 · 4 revisions

Option: /minidmp

By default, PE-sieve extracts and dumps the elements that are detected as potential implants (PEs, and optionally shellcodes). However, sometimes you may like to make a dump of the full process space.

When the option /minidmp is chosen, PE-sieve will create a minidump of the full process that was detected as suspicious (in addition to dumping the implants).

Example:

MiniDump example