Accelerated Windows Memory Dump Analysis, Fifth Edition, Part 2, Revision 3, Kernel and Complete Spaces
Accelerated Windows Memory Dump Analysis, Fifth Edition, Part 2, Revision 3, Kernel and Complete Spaces
Training Course Transcript and WinDbg Practice Exercises with Notes
About the Book
The full-color transcript of Software Diagnostics Services training sessions with 14 step-by-step exercises, notes, source code of specially created modeling applications, and 45 questions and answers. Covers more than 35 crash dump analysis patterns from x64 kernel and complete (physical) memory dumps. Learn how to analyze system crashes and freezes, navigate through kernel and complete spaces, and diagnose patterns of abnormal software behavior with WinDbg debugger. The training uses a unique and innovative pattern-oriented analysis approach developed by Software Diagnostics Institute to speed up the learning curve. Prerequisites: Basic Windows troubleshooting. Audience: Software technical support and escalation engineers, system administrators, security researchers, reverse engineers, malware and memory forensics analysts, software developers and quality assurance engineers, site reliability engineers. The 5th edition was fully reworked with new memory dumps, additional slides, exercises, and analysis patterns. It was further revised with some exercises updated to Windows 11, expanded Q&A, and optional Docker image. The current revision 5.7 uses WinDbg Preview for all exercise transcripts.
Bundles that include this book
Table of Contents
About the Author 5
Presentation Slides and Transcript 7
Practice Exercises 37
Exercise 0: Download, setup, and verify your WinDbg Preview or WinDbg installation, or Docker image 42
Exercise K1: Analysis of a normal kernel dump (64-bit) 56
Exercise K2: Analysis of a kernel dump with pool leak (64-bit) 110
Exercise K3: Analysis of a kernel dump with pool corruption (64-bit) 125
Exercise K4: Analysis of a kernel dump with code corruption (64-bit) 131
Exercise K5: Analysis of a kernel dump with hang I/O (64-bit) 148
Exercise K6: Analysis of a kernel dump with stack overflow (64-bit) 168
Exercise K7: Analysis of a kernel dump with stack overwrite (64-bit) 182
Exercise K8: Analysis of a kernel dump with blocked service process (64-bit) 189
Exercise C1: Analysis of a normal complete dump (64-bit) 204
Exercise C2: Analysis of a problem complete dump (64-bit) 223
Exercise C3: Analysis of a problem complete dump (64-bit) 257
Exercise C4: Analysis of a problem complete dump (64-bit) 270
Exercise C5: Analysis of a problem complete dump (64-bit) 295
Application Source Code 309
AppA 311
AppB 313
AppC 315
AppE 317
AppK 319
ServiceA 320
Selected Q&A 323
Minidump Analysis 349
Scripts and WinDbg Commands 349
Component Identification 352
Raw Stack Data Analysis 357
Symbols and Images 366
Wait Chain (Executive Resources) 369
Other books by this author
The Leanpub 60-day 100% Happiness Guarantee
Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
See full terms
80% Royalties. Earn $16 on a $20 book.
We pay 80% royalties. That's not a typo: you earn $16 on a $20 sale. If we sell 5000 non-refunded copies of your book or course for $20, you'll earn $80,000.
(Yes, some authors have already earned much more than that on Leanpub.)
In fact, authors have earnedover $12 millionwriting, publishing and selling on Leanpub.
Learn more about writing on Leanpub
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
Learn more about Leanpub's ebook formats and where to read them