Run procdump flow
The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.
Role required: sn_si.analyst
This flow is triggered when enriched processes are selected and a Run procdump UI action is executed.
Run Procdump Flow
Reasons the procdump can fail includes:
- Invalid dump path
- Invalid file share path
- Unable to fetch the fully-qualified domin name of the Windows machine the procdump is running on
- The process name is not specified
- The PROCDUMP environment variable not found
A copy of the dump file fails to copy from the dump path to the file share path
Execute procdump action
Execute procdump is a powershell action that runs the procdump on the selected processes, dumps the data into a file, and posts it to a shared site on an internal network. An analyst can then view a deny listed process, highlighted in red in a security incident, and perform additional analysis on the file.
Parent Topic:Security Incident Response Orchestration workflows and activities
Related topics
Create Lookup Request for IoC Changes workflow
Security Incident Response- Get Network Statistics flow