Data Loss Prevention Endpoint PreventData Loss Prevention Endpoint SuiteData Loss Prevention
Issue/Introduction
We found createdump.exe at <dlp agent install directory>\Endpoint Agent\ooxml\publish\createdump.exe It appears to have the ability to create memory space dumps which is above and beyond what a user's local permissions are expected to be capable of, we need to know if this is a security issue.
Resolution
Createdump.exe is part of the .net distribution and is installed to resolve our .net dependency without requiring .net as a prerequisite. The presence of this tool does not give a user anymore access than they already have based on their role.