Collects a driver from live memory or from a memory image of Windows host endpoints.
This audit was formerly known as the w32driver-memoryacquire audit.
This audit cannot be imported into a data acquisition script. See Audits That Cannot Be Imported on page 1.
Supported Platforms
Windows only
Memory-related audits are now supported for host endpoints running the following Windows operating system versions.
Windows 7 (32-bit & 64-bit)
Windows Server 2012 R2 (64-bit)
Windows Server 2016 (64-bit)
Windows Server 2019 (64-bit)
Windows Server 2022 (64-bit)
Windows 8.1 (32-bit & 64-bit)[1]
Windows 10 2015 LTSB, 2016 LTSB, 2019 LTSC
Windows 10 RS1 - 21H2 (64-bit)
Windows 11 21H2 (64-bit)
Input Parameters
The following input parameters are available for this audit.
driver name
Details | Values | Description |
|---|---|---|
Platform | Windows | Windows environments |
Format | String | Valid values are a string of text. |
Required? | no | This parameter is not required. |
Repeatable? | no | This parameter can be specified only once per audit request. It cannot be repeated. |
Valid Values | Specify the driver name to acquire. |
memory file
Details | Values | Description |
|---|---|---|
Platform | Windows | Windows environments |
Format | FilePath | Valid values are a full file path and file name. |
Required? | no | This parameter is not required. |
Repeatable? | no | This parameter can be specified only once per audit request. It cannot be repeated. |
Valid Values | Specify the full path and file name of the file that represents the host endpoint's physical memory. |
Prevent Hibernation
Details | Values | Description |
|---|---|---|
Platform | Windows | Windows environments |
Format | Bool | Valid values are Boolean values. |
Required? | no | This parameter is not required. |
Repeatable? | no | This parameter can be specified only once per audit request. It cannot be repeated. |
Valid Values | Use Boolean values to indicate whether to prevent the host endpoint from entering hibernation while this audit is executed. |
[1] The Agent provides limited support for the driver-memoryacquire audit for host endpoints running Windows 8.1.