Windows 8.1 update: “Live dump” capability

In preparation for refreshing some content in my slide deck for my presentation at Brucon 0x06, I happened upon some functions in the Windows 8.1 kernel I had never seen before.  They were all named with some variation of “LiveDump”.  Here are a few examples:

8129c9fd nt!IopLiveDumpInitiateCorralStateChange ()
8148dbe5 nt!IopLiveDumpWriteBuffer ()
8148d7f3 nt!IopLiveDumpAllocateMappingResources ()
8148d2e9 nt!IoCaptureLiveDump()

I was a little surprised, because I had peeked at 8.1 when it first came out and didn’t notice these.  What the heck is a live dump?  It appears to be a way to save a dump of physical memory (in dump file format) to a flat file using the normal I/O path (it appears the Microsoft developers have an un-implemented option to use the crash dump path – cool!).  Best of all, the functionality is exposed via our old friend NtSystemDebugControl (harkening back to the days of control code 10 that allowed a similar capability).  There are a few restrictions in place, but the good news is the generated dump file doesn’t have to live in the page file (though this would certainly not be the case if the crash path were used).

Stay tuned for more details on this discovery, as well as a tool to leverage the feature.  At Brucon, I will also be releasing a Windbg extension for all things crash dump related.  An upcoming blog post will reveal more details about my upcoming presentation.

Tagged with: ,
Posted in blog, conference
One comment on “Windows 8.1 update: “Live dump” capability
  1. […] wrap up the recent news concerning live dumps, which I discussed here and here, I will cover the topic in a bit more detail and provide full source code to a tool you can use to […]

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s

%d bloggers like this: