In this episode of Defrag Tools, Graham McIntyre joins Andrew Richards and Chad Beeder to talk about the new Active Memory Dump type. This new kernel dump size replaces the Complete Memory Dump type, and although much smaller, is equally as useful.
is there any way to downloads crash dumps?
sysdm.cpl may be faster then Win+Pause
Does complete contain LSASS memory with all the private keys?
Active Memory dump was available since first Win10 Preview in october 2014, not Win10 AU v1607 :S
Wasn't HB Gary able to collect the Uber-dump (RAM + page file) since several years for forensic investigations? I'm looking for that to become freely available. Please record an episode on that topic.