Process Memory Dump via RdrLeakDiag.EXE

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects the use of the Microsoft Windows Resource Leak Diagnostic tool "rdrleakdiag.exe" to dump process memory

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Process started" AND (PROCESSNAME endswith "\rdrleakdiag.exe" OR ORIGINALFILENAME = "RdrLeakDiag.exe") AND (COMMANDLINE contains "-memdmp,/memdmp,–memdmp,—memdmp,―memdmp" OR COMMANDLINE contains "fullmemdmp") AND (COMMANDLINE contains " -o , /o , –o , —o , ―o " OR COMMANDLINE contains " -p , /p , –p , —p , ―p ") select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME

Detection

Execution Mode

realtime

Log Sources

Windows

Author

Cedric MAURUGEON, Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems)