Process Dump 3.0.0
|
Author:
Geoff McDonald
Date: 10/05/26 Size: 495 KB License: Open Source Requires: 11|10|8|7 Downloads: 136 times Restore Missing Windows Files |
Download (32-Bit) Download (64-Bit) Download@MajorGeeks Download@MajorGeeks
|
MajorGeeks: Setting the standard for editor-tested, trusted, and secure downloads since 2002. |
Get free antivirus with AI-powered online scam detection Download Free!
Process Dump is a powerful Command Line tool designed for reverse engineering on Windows systems, specifically focused on capturing malware components from memory for further analysis.
Process Dump offers a comprehensive set of capabilities geared towards advanced process analysis and code extraction. It allows users to dump code from selected processes or all active processes, enabling detailed inspection of running applications. Notably, it detects and extracts hidden modules that may not load properly within those processes, as well as retrieving loose code chunks not linked to a Portable Executable (PE) file. For these extracted code pieces, the tool can construct a PE header and import table, significantly enhancing their usability. Additionally, it aggressively reconstructs imports, further improving the value of the dumped data. The tool also includes a unique close dump monitor mode (-closemon), which enables it to pause and capture hooked processes just before they terminate. Its multi-threading support speeds up dumping across all running processes, while generating a clean hash database lets users create a sanitized environment and bypass known modules in future dumps.
Cybersecurity researchers often encounter malware that is packed and obfuscated to evade antivirus (AV) detection. When these malicious files are executed, they typically unpack or inject a clean version of their code into system memory. A crucial part of malware analysis involves extracting this unpacked code from memory and saving it to disk for subsequent scanning with AV tools or for in-depth examination using static analysis software such as IDA.
Compatible with both 32-bit and 64-bit Windows operating systems, Process Dump offers flexibility, allowing users to extract memory components from specific processes or from all currently running processes. A key feature is its ability to create and use a clean-hash database, allowing the software to skip known files, such as kernel32.dll, during the dumping process.
Process Dump can dump all unknown code from memory (-system), dump specific processes, or monitor processes and dump them before they terminate.
On a clean workstation, generate a baseline database with either:
● pd64.exe -db genquick
● pd64.exe -db gen
Run database generation and dumping as separate commands. For best access, run as Administrator. The default worker count is 16.
Example usage:
● pd64.exe -system
● pd64.exe -pid 419
● pd64.exe -pid 0x1a3
● pd64.exe -pid 0x1a3 -a 0x401000 -o C:\dumps
● pd64.exe -p "chrome[.]exe"
● pd64.exe -p ".*chrome.*"
● pd64.exe -closemon
General Dumping Options
Option / Description
● -system Dumps modules and loose code not matching the clean hash database from all accessible processes.
● -pid < pid > Dumps a specific process. Use decimal or a 0x prefix for a hexadecimal PID.
● -closemon Hooks process termination and dumps before exit. Use in a controlled environment; press Ctrl+C to stop.
● -p < regex > Dumps processes whose entire name matches a case-sensitive regular expression. Multiple matches prompt for confirmation.
● -a < address > Dumps at the specified base address. Requires -pid; accepts decimal or 0x-prefixed hex.
(No spaces in < regex >, etc.)
For more Command Line Arguments and other details, see here.
Process Dump will prove to be an invaluable asset for malware researchers, significantly boosting the effectiveness of memory analysis. By enabling deeper examination of malware behavior and attributes, it stands out as a vital industry resource.
What does Process Dump Provide?
Process Dump offers a comprehensive set of capabilities geared towards advanced process analysis and code extraction. It allows users to dump code from selected processes or all active processes, enabling detailed inspection of running applications. Notably, it detects and extracts hidden modules that may not load properly within those processes, as well as retrieving loose code chunks not linked to a Portable Executable (PE) file. For these extracted code pieces, the tool can construct a PE header and import table, significantly enhancing their usability. Additionally, it aggressively reconstructs imports, further improving the value of the dumped data. The tool also includes a unique close dump monitor mode (-closemon), which enables it to pause and capture hooked processes just before they terminate. Its multi-threading support speeds up dumping across all running processes, while generating a clean hash database lets users create a sanitized environment and bypass known modules in future dumps.
Why Would You Need Process Dump?
Cybersecurity researchers often encounter malware that is packed and obfuscated to evade antivirus (AV) detection. When these malicious files are executed, they typically unpack or inject a clean version of their code into system memory. A crucial part of malware analysis involves extracting this unpacked code from memory and saving it to disk for subsequent scanning with AV tools or for in-depth examination using static analysis software such as IDA.
Compatibility
Compatible with both 32-bit and 64-bit Windows operating systems, Process Dump offers flexibility, allowing users to extract memory components from specific processes or from all currently running processes. A key feature is its ability to create and use a clean-hash database, allowing the software to skip known files, such as kernel32.dll, during the dumping process.
Command Line Arguments
Process Dump can dump all unknown code from memory (-system), dump specific processes, or monitor processes and dump them before they terminate.
On a clean workstation, generate a baseline database with either:
● pd64.exe -db genquick
● pd64.exe -db gen
Run database generation and dumping as separate commands. For best access, run as Administrator. The default worker count is 16.
Example usage:
● pd64.exe -system
● pd64.exe -pid 419
● pd64.exe -pid 0x1a3
● pd64.exe -pid 0x1a3 -a 0x401000 -o C:\dumps
● pd64.exe -p "chrome[.]exe"
● pd64.exe -p ".*chrome.*"
● pd64.exe -closemon
General Dumping Options
Option / Description
● -system Dumps modules and loose code not matching the clean hash database from all accessible processes.
● -pid < pid > Dumps a specific process. Use decimal or a 0x prefix for a hexadecimal PID.
● -closemon Hooks process termination and dumps before exit. Use in a controlled environment; press Ctrl+C to stop.
● -p < regex > Dumps processes whose entire name matches a case-sensitive regular expression. Multiple matches prompt for confirmation.
● -a < address > Dumps at the specified base address. Requires -pid; accepts decimal or 0x-prefixed hex.
(No spaces in < regex >, etc.)
For more Command Line Arguments and other details, see here.
Geek Verdict
Process Dump will prove to be an invaluable asset for malware researchers, significantly boosting the effectiveness of memory analysis. By enabling deeper examination of malware behavior and attributes, it stands out as a vital industry resource.
Editor's Note:
Process Dump does get a hit on VirusTotal, and you may get a warning from your antivirus that the file isn't commonly downloaded.
Screenshot for Process Dump





Tactical Briefings