Accelerated Windows Memory Dump Analysis, Sixth Edition, Part 2, Kernel and Complete Spaces
Accelerated Windows Memory Dump Analysis, Sixth Edition, Part 2, Kernel and Complete Spaces
Training Course Transcript and WinDbg Practice Exercises with Notes
About the Book
The full-color transcript of Software Diagnostics Services training sessions with 14 step-by-step exercises, notes, source code of specially created modeling applications, and 45 questions and answers. Covers more than 35 crash dump analysis patterns from x64 kernel and complete (physical) memory dumps. Learn how to analyze system crashes and freezes, navigate through the kernel and complete spaces, and diagnose patterns of abnormal software behavior with WinDbg debugger. The training uses a unique and innovative pattern-oriented analysis approach developed by Software Diagnostics Institute to speed up the learning curve. Prerequisites: Basic Windows troubleshooting. Audience: Software technical support and escalation engineers, system administrators, security researchers, reverse engineers, malware and memory forensics analysts, software developers and quality assurance engineers, and site reliability engineers. The 6th edition was fully reworked for the latest WinDbg version and includes additional relevant x64 assembly language review and BSOD analysis pattern strategy outline.
Bundles that include this book
Table of Contents
About the Author 5
Presentation Slides and Transcript 7
Review of x64 Disassembly 37
Practice Exercises 49
Exercise 0: Download, setup, and verify your WinDbg or Debugging Tools for Windows installation, or Docker Debugging Tools for Windows image 54
Exercise K1: Analysis of a normal kernel dump (64-bit) 68
Exercise K2: Analysis of a kernel dump with pool leak (64-bit) 122
Exercise K3: Analysis of a kernel dump with pool corruption (64-bit) 137
Exercise K4: Analysis of a kernel dump with code corruption (64-bit) 144
Exercise K5: Analysis of a kernel dump with hang I/O (64-bit) 163
Exercise K6: Analysis of a kernel dump with stack overflow (64-bit) 183
Exercise K7: Analysis of a kernel dump with stack overwrite (64-bit) 198
Exercise K8: Analysis of a kernel dump with blocked service process (64-bit) 204
Exercise C1: Analysis of a normal complete dump (64-bit) 221
Exercise C2: Analysis of a problem complete dump (64-bit) 240
Exercise C3: Analysis of a problem complete dump (64-bit) 274
Exercise C4: Analysis of a problem complete dump (64-bit) 287
Exercise C5: Analysis of a problem complete dump (64-bit) 312
Application Source Code 325
AppA 327
AppB 329
AppC 331
AppE 333
AppK 335
ServiceA 336
Selected Q&A 339
Minidump Analysis 365
Scripts and WinDbg Commands 365
Component Identification 368
Raw Stack Data Analysis 373
Symbols and Images 382
Wait Chain (Executive Resources) 385
Other books by this author
The Leanpub 60 Day 100% Happiness Guarantee
Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
Now, this is technically risky for us, since you'll have the book or course files either way. But we're so confident in our products and services, and in our authors and readers, that we're happy to offer a full money back guarantee for everything we sell.
You can only find out how good something is by trying it, and because of our 100% money back guarantee there's literally no risk to do so!
So, there's no reason not to click the Add to Cart button, is there?
See full terms...
Earn $8 on a $10 Purchase, and $16 on a $20 Purchase
We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.
(Yes, some authors have already earned much more than that on Leanpub.)
In fact, authors have earnedover $13 millionwriting, publishing and selling on Leanpub.
Learn more about writing on Leanpub
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
Learn more about Leanpub's ebook formats and where to read them