Invoke a process dump for an enriched process in Windows
A security analyst can run a process dump on a specific process, dump it into a file, and post it to a shared site on an internal network. An analyst can then view a deny listed process, highlighted in red in a security incident, and perform additional analysis.
Before you begin
The following are required:
Role required: sn_si.analyst- A client running Windows Vista or higher, or a server running Windows Server 2008 or higher.
- The ProcDump command-line utility installed, with a system environment variable that points to the procdump executable file path. The name of the variable must be PROCDUMP. This name is used in a powershell script.