Skip to content

Instantly share code, notes, and snippets.

@mattifestation
Last active September 16, 2019 04:58
Show Gist options
  • Star 9 You must be signed in to star a gist
  • Fork 10 You must be signed in to fork a gist
  • Save mattifestation/7fe1df7ca2f08cbfa3d067def00c01af to your computer and use it in GitHub Desktop.
Save mattifestation/7fe1df7ca2f08cbfa3d067def00c01af to your computer and use it in GitHub Desktop.
Automatically capture a full PowerShell memory dump upon any PowerShell host process termination
$EventFilterArgs = @{
EventNamespace = 'root/cimv2'
Name = 'PowerShellProcessStarted'
Query = 'SELECT FileName, ProcessID FROM Win32_ModuleLoadTrace WHERE FileName LIKE "%System.Management.Automation%.dll"'
QueryLanguage = 'WQL'
}
$Filter = New-CimInstance -Namespace root/subscription -ClassName __EventFilter -Property $EventFilterArgs
$CommandLineConsumerArgs = @{
Name = 'PowershellMemoryCapture'
CommandLineTemplate = 'procdump.exe -accepteula -g -e -t -ma %ProcessID% C:\dumps'
}
$Consumer = New-CimInstance -Namespace root/subscription -ClassName CommandLineEventConsumer -Property $CommandLineConsumerArgs
$FilterToConsumerArgs = @{
Filter = [Ref] $Filter
Consumer = [Ref] $Consumer
}
$FilterToConsumerBinding = New-CimInstance -Namespace root/subscription -ClassName __FilterToConsumerBinding -Property $FilterToConsumerArgs
<# Cleanup
Get-CimInstance -Namespace root/subscription -ClassName __EventFilter | Remove-CimInstance
Get-CimInstance -Namespace root/subscription -ClassName __EventConsumer | Remove-CimInstance
Get-CimInstance -Namespace root/subscription -ClassName __FilterToConsumerBinding | Remove-CimInstance
#>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment