[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftOGurtdFpXIk62bwMa7jaRAiGLDuBjANbqK-9y-TLCM":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},866,"How can I automate scanning all DLLs in the Windows directory for export functions like MiniDumpW?","A PowerShell script can recursively traverse `C:\\Windows`, obtain each DLL's absolute path, and use a function like `Get-Exports` (from the PowerShell-Suite) to list export function names. The article provides a script that filters for `MiniDumpW` and other exports. It handles the path format issue by stripping the `Microsoft.PowerShell.Core\\FileSystem::` prefix. The complete script is shared on GitHub. This technique is useful for discovering alternative DLLs for [lateral movement or privilege escalation](\u002Fnews\u002Fpenetration-basics-minio-version-detection-1).","\u003Cp>A PowerShell script can recursively traverse `C:\\Windows`, obtain each DLL&#39;s absolute path, and use a function like `Get-Exports` (from the PowerShell-Suite) to list export function names. The article provides a script that filters for `MiniDumpW` and other exports. It handles the path format issue by stripping the `Microsoft.PowerShell.Core\\FileSystem::` prefix. The complete script is shared on GitHub. This technique is useful for discovering alternative DLLs for [lateral movement or privilege escalation](\u002Fnews\u002Fpenetration-basics-minio-version-detection-1).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexploitation-testing-of-minidumpwritedump-via-com-services-dll\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-automate-scanning-all-dlls-in-the-windows-directory-for-export-functio-1777481662645","PowerShell script, export function scanning, MiniDumpW, Windows DLLs, automation, penetration testing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},211,"Exploitation Testing of \"MiniDumpWriteDump via COM+ Services DLL\"","exploitation-testing-of-minidumpwritedump-via-com-services-dll","Learn to exploit MiniDumpWriteDump via COM+ Services DLL for process memory dumps. Includes PowerShell automation, permission handling, and exploitation analysis for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I studied a technique introduced in odzhan's article, which uses the export function MiniDump from C:\\windows\\system32\\comsvcs.dll to dump the memory file of a specified process.\u003C\u002Fp>\u003Cp>Article address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmodexp.wordpress.com\u002F2019\u002F08\u002F30\u002Fminidumpwritedump-via-com-services-dll\u002F\u003C\u002Fp>\u003Cp>This article will combine my own experience to supplement the points that need attention during testing, extend the methods, and analyze exploitation ideas. Write a PowerShell script to automatically scan all DLLs in the system directory for export functions, check for other usable DLLs, and introduce the details of script implementation.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Common methods for dumping memory files of specified processes\u003C\u002Fli>\u003Cli>Method for dumping memory files of specified processes using comsvcs.dll\u003C\u002Fli>\u003Cli>Writing a script to automatically scan DLL export functions\u003C\u002Fli>\u003Cli>Exploitation analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Common methods for dumping memory files of specified processes\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, the most common method involves dumping the lsass.exe process to obtain plaintext passwords and hashes\u003C\u002Fp>\u003Cp>The principle relies on using the API MiniDumpWriteDump. Reference material:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fminidumpapiset\u002Fnf-minidumpapiset-minidumpwritedump\u003C\u002Fp>\u003Cp>Common implementation methods are as follows:\u003C\u002Fp>\u003Ch3>1. procdump\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>procdump.exe -accepteula -ma lsass.exe lsass.dmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. C++ implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fkillswitch-GUI\u002Fminidump-lib\u003C\u002Fp>\u003Ch3>3. PowerShell implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FOut-Minidump.ps1\u003C\u002Fp>\u003Ch3>4. C# implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FSharpDump\u003C\u002Fp>\u003Ch2>0x03 Method to dump specified process memory files using comsvcs.dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Odzhan presented three methods in the article\u003C\u002Fp>\u003Ch3>1. Via rundll32\u003C\u002Fh3>\u003Cp>Example parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the example, the pid of lsass.exe is 808\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Here, attention must be paid to permission issues; when dumping the memory file of a specified process, the SeDebugPrivilege permission needs to be enabled\u003C\u002Fp>\u003Cp>Under cmd with administrator privileges, SeDebugPrivilege permission is supported by default, but its status is Disabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017257646_0_80a9b058db.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, directly executing the rundll32 command under cmd to attempt to dump the memory file of a specified process will fail because the SeDebugPrivilege permission cannot be enabled\u003C\u002Fp>\u003Cp>Here is one of my solutions:\u003C\u002Fp>\u003Cp>Under PowerShell with administrator privileges, SeDebugPrivilege permission is supported by default, and its status is Enabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017282982_1_cb6c56ee9f.jpeg\">\u003C\u002Fp>\u003Cp>Thus, it can be achieved by executing the rundll32 command via PowerShell, with an example command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Implementation via VBS\u003C\u002Fh3>\u003Cp>The original text provides complete implementation code\u003C\u002Fp>\u003Cp>The execution parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript 1.vbs lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The VBS script first enables SeDebugPrivilege, then executes the rundll32 command, tested successfully\u003C\u002Fp>\u003Ch3>3. Implementation via C\u003C\u002Fh3>\u003Cp>The original text provides complete implementation code\u003C\u002Fp>\u003Cp>The code first enables SeDebugPrivilege, then calls the export function MiniDumpW from comsvcs.dll, tested successfully\u003C\u002Fp>\u003Ch2>0x04 Writing a script to automate scanning DLL export functions\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After studying odzhan's article, I had a question:\u003C\u002Fp>\u003Cp>Are there other usable DLLs in the Windows system directory?\u003C\u002Fp>\u003Cp>Thus, I attempted to filter the export functions of all DLLs in the system directory via a script to check if they contain the export function MiniDumpW\u003C\u002Fp>\u003Cp>The script implementation needs to consider the following two issues:\u003C\u002Fp>\u003Ch3>1. Traverse the specified directory to obtain all DLLs\u003C\u002Fh3>\u003Cp>The test code for traversing the path C:\\windows is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path 'C:\\windows'  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>    $file.PSPath\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Since there are multiple levels of directories, it is necessary to obtain the absolute path of the DLL, and the format of $file.PSPath is Microsoft.PowerShell.Core\\FileSystem::C:\\windows\\RtlExUpd.dll, the actual path needs to remove the prefix\u003C\u002Fp>\u003Cp>The optimized code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path 'C:\\windows'  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>    $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain the export functions of the specified DLL\u003C\u002Fh3>\u003Cp>You can refer to https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1\u003C\u002Fp>\u003Cp>Based on this, optimize to achieve automated processing of the entire process\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code for filtering C:\\Windows is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\u002FGet-AllExports.ps1\u003Cbr>$Path = 'C:\\Windows'\u003Cbr>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path $Path  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>#   $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>    Get-Exports -DllPath $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test system: Win7x64\u003C\u002Fp>\u003Cp>Partial results:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[+] C:\\windows\\system32\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\windows\\system32\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\windows\\system32\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\Syswow64\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\Syswow64\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\Syswow64\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_a6821d2940c2bcdc\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_a6821d2940c2bcdc\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_4a6381a588654ba6\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_4a6381a588654ba6\\dbghelp.dll--&gt;MiniDumpWriteDump\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test results are as follows:\u003C\u002Fp>\u003Ch4>1. For processes with different architectures, the available DLLs differ.\u003C\u002Fh4>\u003Cp>For 32-bit processes, both 32-bit and 64-bit DLLs can be used:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\windows\\system32\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For 64-bit processes, 64-bit DLLs can be used:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\windows\\system32\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Cannot use 32-bit DLL:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>2. dbghelp.dll corresponds to API MiniDumpWriteDump\u003C\u002Fh4>\u003Ch4>3. The exported function minidumpmode in SOS.dll\u003C\u002Fh4>\u003Cp>Used to prevent execution of unsafe commands when using minidump. 0 means disable this feature, 1 means enable. Default is 0\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If you want to dump the memory file of a specified process, you can use the new method. Example command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where comsvcs.dll can be replaced with the following DLLs:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The advantage of this method is that it does not require uploading files and can be implemented using the dlls included by default in the system.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on odzhan's article, this paper supplements the points to note during testing, extends the methods, and analyzes exploitation ideas. A PowerShell script is written to automate scanning of all dll export functions in the system directory.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I studied a technique introduced in odzhan's article, which uses the export function MiniDump from C:\\windows\\system32\\comsvcs.dll to dump the memory file of a specified process.\u003C\u002Fp>\u003Cp>Article address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmodexp.wordpress.com\u002F2019\u002F08\u002F30\u002Fminidumpwritedump-via-com-services-dll\u002F\u003C\u002Fp>\u003Cp>This article will combine my own experience to supplement the points that need attention during testing, extend the methods, and analyze exploitation ideas. Write a PowerShell script to automatically scan all DLLs in the system directory for export functions, check for other usable DLLs, and introduce the details of script implementation.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Common methods for dumping memory files of specified processes\u003C\u002Fli>\u003Cli>Method for dumping memory files of specified processes using comsvcs.dll\u003C\u002Fli>\u003Cli>Writing a script to automatically scan DLL export functions\u003C\u002Fli>\u003Cli>Exploitation analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Common methods for dumping memory files of specified processes\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, the most common method involves dumping the lsass.exe process to obtain plaintext passwords and hashes\u003C\u002Fp>\u003Cp>The principle relies on using the API MiniDumpWriteDump. Reference material:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fminidumpapiset\u002Fnf-minidumpapiset-minidumpwritedump\u003C\u002Fp>\u003Cp>Common implementation methods are as follows:\u003C\u002Fp>\u003Ch3>1. procdump\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>procdump.exe -accepteula -ma lsass.exe lsass.dmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. C++ implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fkillswitch-GUI\u002Fminidump-lib\u003C\u002Fp>\u003Ch3>3. PowerShell implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FOut-Minidump.ps1\u003C\u002Fp>\u003Ch3>4. C# implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FSharpDump\u003C\u002Fp>\u003Ch2>0x03 Method to dump specified process memory files using comsvcs.dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Odzhan presented three methods in the article\u003C\u002Fp>\u003Ch3>1. Via rundll32\u003C\u002Fh3>\u003Cp>Example parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the example, the pid of lsass.exe is 808\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Here, attention must be paid to permission issues; when dumping the memory file of a specified process, the SeDebugPrivilege permission needs to be enabled\u003C\u002Fp>\u003Cp>Under cmd with administrator privileges, SeDebugPrivilege permission is supported by default, but its status is Disabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017257646_0_80a9b058db-1.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, directly executing the rundll32 command under cmd to attempt to dump the memory file of a specified process will fail because the SeDebugPrivilege permission cannot be enabled\u003C\u002Fp>\u003Cp>Here is one of my solutions:\u003C\u002Fp>\u003Cp>Under PowerShell with administrator privileges, SeDebugPrivilege permission is supported by default, and its status is Enabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017282982_1_cb6c56ee9f-1.jpeg\">\u003C\u002Fp>\u003Cp>Thus, it can be achieved by executing the rundll32 command via PowerShell, with an example command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Implementation via VBS\u003C\u002Fh3>\u003Cp>The original text provides complete implementation code\u003C\u002Fp>\u003Cp>The execution parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript 1.vbs lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The VBS script first enables SeDebugPrivilege, then executes the rundll32 command, tested successfully\u003C\u002Fp>\u003Ch3>3. Implementation via C\u003C\u002Fh3>\u003Cp>The original text provides complete implementation code\u003C\u002Fp>\u003Cp>The code first enables SeDebugPrivilege, then calls the export function MiniDumpW from comsvcs.dll, tested successfully\u003C\u002Fp>\u003Ch2>0x04 Writing a script to automate scanning DLL export functions\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After studying odzhan's article, I had a question:\u003C\u002Fp>\u003Cp>Are there other usable DLLs in the Windows system directory?\u003C\u002Fp>\u003Cp>Thus, I attempted to filter the export functions of all DLLs in the system directory via a script to check if they contain the export function MiniDumpW\u003C\u002Fp>\u003Cp>The script implementation needs to consider the following two issues:\u003C\u002Fp>\u003Ch3>1. Traverse the specified directory to obtain all DLLs\u003C\u002Fh3>\u003Cp>The test code for traversing the path C:\\windows is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path 'C:\\windows'  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>    $file.PSPath\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Since there are multiple levels of directories, it is necessary to obtain the absolute path of the DLL, and the format of $file.PSPath is Microsoft.PowerShell.Core\\FileSystem::C:\\windows\\RtlExUpd.dll, the actual path needs to remove the prefix\u003C\u002Fp>\u003Cp>The optimized code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path 'C:\\windows'  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>    $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain the export functions of the specified DLL\u003C\u002Fh3>\u003Cp>You can refer to https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1\u003C\u002Fp>\u003Cp>Based on this, optimize to achieve automated processing of the entire process\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code for filtering C:\\Windows is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\u002FGet-AllExports.ps1\u003Cbr>$Path = 'C:\\Windows'\u003Cbr>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path $Path  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>#   $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>    Get-Exports -DllPath $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test system: Win7x64\u003C\u002Fp>\u003Cp>Partial results:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[+] C:\\windows\\system32\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\windows\\system32\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\windows\\system32\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\Syswow64\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\Syswow64\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\Syswow64\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_a6821d2940c2bcdc\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_a6821d2940c2bcdc\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_4a6381a588654ba6\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_4a6381a588654ba6\\dbghelp.dll--&gt;MiniDumpWriteDump\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test results are as follows:\u003C\u002Fp>\u003Ch4>1. For processes with different architectures, the available DLLs differ.\u003C\u002Fh4>\u003Cp>For 32-bit processes, both 32-bit and 64-bit DLLs can be used:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\windows\\system32\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For 64-bit processes, 64-bit DLLs can be used:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\windows\\system32\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Cannot use 32-bit DLL:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>2. dbghelp.dll corresponds to API MiniDumpWriteDump\u003C\u002Fh4>\u003Ch4>3. The exported function minidumpmode in SOS.dll\u003C\u002Fh4>\u003Cp>Used to prevent execution of unsafe commands when using minidump. 0 means disable this feature, 1 means enable. Default is 0\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If you want to dump the memory file of a specified process, you can use the new method. Example command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where comsvcs.dll can be replaced with the following DLLs:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The advantage of this method is that it does not require uploading files and can be implemented using the dlls included by default in the system.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on odzhan's article, this paper supplements the points to note during testing, extends the methods, and analyzes exploitation ideas. A PowerShell script is written to automate scanning of all dll export functions in the system directory.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",724,"Onedaysec",4,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"MiniDumpWriteDump via COM+ Services DLL Exploitation Testing Guide","MiniDumpWriteDump, comsvcs.dll, process memory dump, lsass.exe, exploitation testing, PowerShell script, DLL export functions, SeDebugPrivilege, penetration testing, memory forensics",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],865,864,863,862,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.140Z","2026-07-23T16:02:12.718Z","draft","2026-07-23T16:15:13.289Z"]