This document describes how to collect crash dumps on Windows for the sfc.exe process.
Platform: Windows endpoint
Product: Cisco Secure Endpoint connector
Tools: Windows Command Prompt; Microsoft Sysinternals ProcDump (procdump64.exe)
Assumed knowledge:
This document is not restricted to software and hardware versions. The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. Review the potential impact of any command before use on a live network.
1. Download Procdump (to be used as the AeDebug postmortem debugger) from Sysinternals Suite.
2. Extract procdump64.exe to the C: drive and create the Dumps folder for crash dump collection.
1. Set procdump64.exe as the automatic debugger in the Windows postmortem debugging registry configuration (AeDebug) with this command. When a program crashes, ProcDump saves the crash dump in the specified folder.
procdump64.exe -ma -i C:\Dumps
2. Navigate to the C:\Dumps folder. Zip it and share it for analysis.
1. To uninstall procdump64.exe, use this command.
procdump64.exe -u
1. Use this command to create a dump on demand.
procdump64.exe -accepteula -ma -e -x c:\Dumps <PID | Process Name>
Example for sfc.exe.
procdump64.exe -accepteula -ma -e -x c:\Dumps "%ProgramFiles%\Cisco\AMP\8.6.1.30582\sfc.exe"
2. Navigate to the C:\Dumps folder. Zip it and share it for analysis.
Crash dumps can occupy a significant amount of disk space, so it is important to stop procdump once the collection is complete. You can also use the workaround to compress the size of the folder.
Use this command in the command prompt to enable compression.
compact /c /s:c:\Dumps
1. Navigate to Properties for the Dumps folder and check the original size of the folder on disk.
2. In Properties, click Advanced, select Compress contents to save disk space, and click OK to apply the change. This process can take several minutes.
3. In the end, you can observe that the folder size has significantly reduced, almost reaching half of its original size.
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
24-Mar-2025
|
Initial Release |