Microsoft documents ProcDump as a legitimate Sysinternals command-line utility for capturing process dump files on Windows, including full and mini dumps triggered by crashes, hangs, CPU spikes, memory thresholds, and other conditions. The tool supports extensive command-line options and can be used for postmortem debugging, making it common in enterprise troubleshooting workflows.
Splunk Threat Research highlighted that attackers can abuse ProcDump to dump the LSASS process and extract credentials, particularly when the binary is renamed to evade simple detections. The hunting logic focuses on Windows process-creation telemetry where the executable's OriginalFileName remains procdump but the running file name is different, and the command line references lsass with dump options such as -ma or -mm; the behavior is mapped to MITRE ATT&CK T1003.001 for LSASS memory credential access.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the hunting detection "Dump LSASS via procdump Rename" from its content library in version 5.2.0 and indicated it was replaced by "Dump LSASS via procdump." The detection had been intended to identify renamed ProcDump binaries used to dump LSASS memory.
Microsoft Learn published the ProcDump Sysinternals documentation page describing the utility's process-monitoring and dump-generation capabilities, supported dump types, triggers, and platform support. The page also links to ProcDump versions for Linux and Mac.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.