- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-27-2026 09:55 AM
I have a question.
When we perform a Dump Alert and get the ZIP file, how can we analyze it in more detail?
For example, if I want to see the .ps1 file that a particular user executed on the machine and that triggered the alert, would that file be included in the dump?
I’ve already searched everywhere, but I can’t find it. I can see a folder called “RecentFiles”, but all the files have strange names, so I’m not sure how to identify them.
Does anyone know how we can analyze the dump in more detail?
I was able to download the Alert Dump, but I couldn’t find the PowerShell script that was executed. I’d like to understand whether the actual file/script that triggered the alert should be included in the dump and, if so, how I can identify it.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

