Reminder that creating a memory dump of Outlook.exe not only produces access tokens but also potentially sensitive email content.
Conversation
Not a windows person but surely most people don't have coredumps enabled in windows, that sounds like an insider build option.
1
1
Okay, so like Linux then. Is there a Windows equivalent to the “undumpable” prctl()?
(this makes it so that a process’s memory becomes readable only be root and it can only be ptraced by root. A process does not need to be privileged to active this mode)
1



