Using procdump on Linux to dump credentials
infonews
security
Source: Embrace The RedAugust 9, 2021
Summary
Procdump is a tool that creates core dumps (snapshots of a program's memory) and can be installed on Linux systems, though it receives less attention from security professionals there than on Windows. An attacker with access to a Linux system can use procdump to dump the memory of running processes and search through them for sensitive information like passwords and credentials, as demonstrated in a scenario where an attacker extracts a password from a user's text editor process.
Classification
Attack SophisticationModerate
Original source: https://embracethered.com/blog/posts/2021/linux-procdump/
First tracked: February 12, 2026 at 02:20 PM
Classified by LLM (prompt v3) · confidence: 95%