Creating a process memory dump retrieval task

You can get a memory dump file from selected Kaspersky Endpoint Agent for Windows hosts. To do so, you must create a process memory dump retrieval task.

To create a process memory dump retrieval task:

  1. Select the Tasks section in the program web interface window.

    This opens the task table.

  2. Click Add and select Get process memory dump.

    This opens the task creation window.

  3. Configure the following settings:
    1. Process ID is the ID of the process for which you want to get a memory dump.
    2. MD5/SHA256 is the MD5 or SHA256 hash of the file of the process of which you want to get a memory dump. This field is optional.
    3. Description is the task description. This field is optional.
    4. Hostis the name or IP address of the host to which you want to assign the task.

      You can specify only one host.

      The process memory dump task can only be assigned to hosts with Kaspersky Endpoint Agent for Windows version 3.13 or later.

  4. Click Add.

The process memory dump retrieval task is created. The task runs automatically after it is created.

The task creates a ZIP archive in Storage, which contains a file with information about the process and a process memory dump file. You can download the archive to your local computer.

If the task results in an error, the archive file contains the description of the error.

If you are using the distributed solution and multitenancy mode, the archive is placed in Storage of the Central Node server to which the host specified in the Host field is connected.

Users with the Security auditor role cannot create this task.

Users with the Security officer role do not have access to tasks.

See also

Managing tasks

Viewing the task table

Viewing information about a task

Creating a process termination task

Creating a data collection task

Creating a task to scan hosts using YARA rules

Creating a service management task

Creating an NTFS metafile retrieval task

Creating a registry key retrieval task

Creating a program execution task

Creating a get file task

Creating a file deletion task

Creating a file quarantine task

Creating a quarantined file recovery task

Creating a copy of a task

Deleting tasks

Filtering tasks by creation time

Filtering tasks by type

Filtering tasks by name

Filtering tasks by file name and path

Filtering tasks by description

Filtering tasks by server name

Filtering tasks based on the name of the user that created the task

Filtering tasks by processing status

Clearing a task filter

Page top