Retrieving a process from a full memory dump

I reached an error, but I was not able to dump the process. I created a system full memory dump. How can I extract process dumpusing it?
Windows.

+4
source share
1 answer

You can not. In general, some segments of memory belonging to your process may be unloaded and may not be in physical memory. This means that with a full core memory dump, you are not guaranteed to recover the process address space.

In many cases, you can extract useful process information from a core dump. However, there are two limitations:

  • The memory can be unloaded, as I mentioned.
  • WinDbg . SOS, .
+5

Source: https://habr.com/ru/post/1529484/


All Articles