---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Run procdump flow

# Run procdump flow {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Run procdump flow runs a process dump on a specified process and saves it to a file that can be targeted by security analysts.
Role required: sn_si.analyst
This flow is triggered when enriched processes are selected and a Run procdump UI action is executed. Figure 1. Run procdump  
Reasons the procdump can fail includes:

* Invalid dump path
* Invalid file share path
* Unable to fetch the fully-qualified domin name of the Windows machine the procdump is running on
* The process name is not specified
* The PROCDUMP environment variable not found
* A copy of the dump file fails to copy from the dump path to the file share path
{#invoke_procdump__ul_ugy_4sp_rdc}
* **[Execute procdump action](https://servicenow-prod.fluidtopics.net/b9QhQkXGJrHQAI2b5es_3g)**   
  Execute procdump is a powershell action that runs the procdump on the selected processes, dumps the data into a file, and posts it to a shared site on an internal network. An analyst can then view a deny listed process, highlighted in red in a security incident, and perform additional analysis on the file.

**Related tasks**   

* [Create Lookup Request for IoC Changes workflow](https://servicenow-prod.fluidtopics.net/AhU0IdEvOfk4klIR2~5Y8w "The Security Incident Response - Create Lookup Request for IoC Changes flow is triggered by the Lookup Security Incident Observables scheduled job to automatically look up IoCs that are added or changed. Malware scans are triggered only when new data is entered and only the new data is scanned.")
* [Security Incident Response- Get Network Statistics flow](https://servicenow-prod.fluidtopics.net/Pc5vJrClrjQg931AP9fBXQ "The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.")
* [Security Incident Response - Get Running Services workflow](https://servicenow-prod.fluidtopics.net/G5KU_I510ZVVJJ4QZN_pQQ "The Security Incident Response - Get Running Services workflow retrieves a list of running services from Windows-based, ServiceNow, configuration items (CIs). This workflow is used for incident enrichment during investigations.")
* [Security Incident - Evaluate response task outcome workflow](https://servicenow-prod.fluidtopics.net/swGPjdmlpa4BbNNdveRajg "Security Incident - Evaluate Response task outcome workflow determines the task to use, invokes a chosen workflow and evaluation script based on the outcome evaluator record provided as input to the chosen workflow.")

