Windows Process Creation: createdump.exe Dumping Memory with Full and Name Flags
Flags and .dmp output usage indicate createdump.exe dumping process memory on Windows.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-01-04
- Updated
- 2026-07-31
ATT&CK techniques
Defense Evasion → Cred AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events where createdump.exe is executed with command-line arguments indicating a full process memory dump and a named output. Such memory dumping can be used to extract sensitive data from running processes, including credentials or other in-memory artifacts. It relies on Windows process creation telemetry, matching both the image path (createdump.exe) and specific CLI flag patterns in the command line.
Reporting behind it
- crowdstrike.comhttps://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/
- twitter.comhttps://twitter.com/bopin2020/status/1366400799199272960
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_createdump_lolbin_execution.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: createdump.exe Dumping Memory with Full and Name Flags"
id: f28f79ec-c12b-487b-b94d-195a1bc1b728
related:
- id: 1a1ed54a-2ba4-4221-94d5-01dee560d71e
type: similar
- id: 515c8be5-e5df-4c5e-8f6d-a4a2f05e4b48
type: derived
status: test
description: This rule flags Windows process creation events where createdump.exe is executed with command-line arguments indicating a full process memory dump and a named output. Such memory dumping can be used to extract sensitive data from running processes, including credentials or other in-memory artifacts. It relies on Windows process creation telemetry, matching both the image path (createdump.exe) and specific CLI flag patterns in the command line.
references:
- https://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/
- https://twitter.com/bopin2020/status/1366400799199272960
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_createdump_lolbin_execution.yml
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-01-04
modified: 2022-08-19
tags:
- attack.stealth
- attack.t1036
- attack.t1003.001
- attack.credential-access
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \createdump.exe
- OriginalFileName: FX_VER_INTERNALNAME_STR
selection_cli:
CommandLine|contains:
- " -u "
- " --full "
- " -f "
- " --name "
- ".dmp "
condition: all of selection_*
falsepositives:
- Command lines that use the same flags
level: high
license: DRL-1.1