ProcDump v10.1, RDCMan v2.82, Sigcheck v2.82 and Sysmon v13.23
Published Jul 27 2021 11:15 AM 8,117 Views
Microsoft

ProcDump v10.1

This update to ProcDump, a command-line utility for generating memory dumps from running processes, adds a new option (-dc) for specifying a dumpfile comment and supports "triage" dumps (-mt).
 

RDCMan v2.82

This RDCMan update adds a toggle for bitmap caching and fixes a series of crashes.
 

Sigcheck v2.82

This Sigcheck update fixes a crash occurring when analyzing unsigned files on VirusTotal.
 

Sysmon v13.23

This Sysmon update fixes a bug where rules with long names were incorrectly processed and a rare out of memory crash occurring on 32-bit systems.
 
5 Comments
Copper Contributor
Copper Contributor

Guys, I just tested v13.23 for a bug I reported and it seems to be fixed. Many thanks! Very appreciated.

https://docs.microsoft.com/en-us/answers/questions/450750/sysmon-bug.html?childToView=494986#answer-...

Brass Contributor

Hello,

 

the new porcdum 10.1 is still not working with Windows Server 2016 (1607)

 

https://docs.microsoft.com/en-us/answers/questions/500002/new-procdump-not-working-in-window-server-...

 

When this ist fixed ?

Copper Contributor

The -dc and -mt options are not documented https://docs.microsoft.com/en-us/sysinternals/downloads/procdump and don't appear in any examples. Can you reach out to the SysInternals content management to fix this ?

 

Thanks

Copper Contributor

I made a post on an ms forum, Procdump Invoking LSASS. Take a look to see if I'm accurate the process timeline. https://docs.microsoft.com/en-us/answers/questions/686828/procdump-invoking-lsass.html 

Co-Authors
Version history
Last update:
‎Jul 27 2021 11:15 AM
Updated by: