I want to dump memory of windows process using just command line and without 3rd party tools. Is that possible if we assume that all necessary privileges aquired.
Maybe it is possible to do using powershell? I have found it possible using procdump
utility but this one is from sysinternals imho.
Best Answer
You can use Out-Minidump function for PowerShell:
Basic usage:
Enable PowerShell script execution via Set-ExecutionPolicy cmdlet. It should be
Bypass
,Unrestricted
orRemoteSigned
. Details:Download
Out-Minidump.ps1
Unblock it using File properties in Explorer (alternate ways)
Launch PowerShell and dot source function from the
Out-Minidump.ps1
(note first dot):