Red Team | Weaponizing Windows Crash Dumps

Red Team | Weaponizing Windows Crash Dumps

🎙 Jason Mull 👥 70K 📅 February 17, 2026 ⏱ 28 min 👁 228 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

crash dumpmemory analysiscredential harvestingliving off the landdetection evasion

Summary

Jason Mull presents a technique for leveraging Windows crash dumps as an offensive security tool. He explains the different types of crash dumps (complete, active, automatic) and how to analyze them using tools like Volatility and MemProcFS. The value lies in the lack of detection coverage for crash dump interaction, as evidenced by limited MITRE ATT&CK mappings. He demonstrates how to extract domain credentials from registry hives and LSASS process memory, browser cookies and credentials, and even master passwords from password managers like Bitwarden, all from offline crash dump analysis. He also provides detection and mitigation strategies, including event ID 101 monitoring, registry key tracking, and PowerShell scripts to search for crash dump files. The talk concludes with recommendations for organizations to evaluate their crash dump policies and disable automatic creation if not needed.

134 words

Critical Evaluation

Value of the Information & Strength of the Argument

The presentation provides valuable insights into an overlooked attack surface. The speaker demonstrates a clear understanding of the subject and supports his claims with practical examples and demonstrations. The argumentation is logical and well-structured, moving from background to exploitation techniques to detection. However, the talk is based on personal research and lacks external validation or comparison with other studies.

Scientific Rigor, Source Quality, Title Accuracy

The speaker references MITRE ATT&CK, tools like Volatility, MemProcFS, and Mimikatz, and mentions a Sigma rule he published. He also mentions discussions with Bitwarden and Chrome regarding the password manager issue. The title accurately reflects the content. The talk is well-organized and the technical details are accurate based on current knowledge.

125 words

Title / Content Match

The title accurately reflects the content, which focuses on using Windows crash dumps for offensive purposes.

Quality & Reliability

7/10

Presentation by an experienced security professional based on original research conducted as part of a SANS master's program. The methodology is clearly explained and demonstrated with practical examples. However, the talk is not peer-reviewed and relies on the speaker's personal findings and tool usage.

Key Moments

Cited Sources

  • MITRE ATT&CK — Referenced for lack of detection techniques for crash dumps.
  • Volatility Framework — Mentioned as a standard tool for memory analysis.
  • MemProcFS — Tool used for browsing crash dump contents.
  • Mimikatz — Referenced for credential extraction.
  • Sigma rule — Speaker mentioned publishing a Sigma rule for detecting crash dump creation.

Concurring Sources

Contribution & Novelties

This talk highlights a novel offensive technique that exploits Windows crash dumps, which are often overlooked by security controls. The speaker demonstrates how to extract sensitive information offline, bypassing detection. The novelty lies in the application of existing memory analysis techniques to crash dumps for offensive purposes, rather than just forensic investigation.

Pour aller plus loin :

90 words

Radar Profile

The radar profile shows high scores in information quantity and technical level, indicating a detailed and technical presentation. The quality and reliability scores are moderate, reflecting the lack of peer review and reliance on personal research. The overall balance suggests a valuable but not fully verified source.

Reliability 7/10

💬 No comments were provided for analysis.