Env.
Virtual Machine
Target VM : win7x86 ( Build 7600) Based on ESXi 5.0
Process VM : Windows 7 SP1 x86 Build 7601
Tools
Name | Version |
---|---|
vmss2core-Linux64 | January 13, 2017 v1.0.1 |
WinDbg | 6.11.0001.404 x86 |
WinSCP | 5.9.3 Build 7136 |
mimilib.dll | win32 from mimikatz_trunk2.1 20160229 |
Step
Get dmp file
- Pause the Running Target VM.
- Copy vmss2core-Linux64 to ESXi (/vmfs/volumes/…/win7x86/) with WinSCP.
- Use vmss2core to convert win7x86-xxx.vmss into a dmp file(memory.dmp).
- Copy memory.dmp to Process VM (c:/vmss/) with WinSCP.
/vmfs/volumes/589af095-50718614-d536-005056881c2e/win7x86 # ./vmss2core-Linux64 -W7600 "win7x86-bfdbf0ed.vmss"
vmss2core version 8437677 Copyright (C) 1998-2017 VMware, Inc. All rights reserved.
Win32: found DDB at PA 0x2779be8
Win32: MmPfnDatabase=0x827b9700
Win32: PsLoadedModuleList=0x82799810
Win32: PsActiveProcessHead=0x82791e98
Win32: KiBugcheckData=0x827b1a00
Win32: KernBase=0x82651000
Win32: NtBuildLab=0x826a1068
CoreDumpScanWin32: MinorVersion set to 7600
... 10 MBs written.
... 20 MBs written.
... 30 MBs written.
...
... 1010 MBs written