O'Reilly logo

Accelerated Windows Memory Dump Analysis: Training Course Transcript and WinDbg Practice Exercises with Notes, Fourth Edition by Software Diagnostics Services, Dmitry Vostokov

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Selected Q&A

 

Q. When is it useful to enable pool tagging?

A. Pool tagging is enabled by default. In case, you suspect certain drivers corrupting pools you should enable Special Pool in Driver Verifier. Here I refer you to Windows Internals, 5th edition, pages 799 – 801 for details.

Q. Can you give some basics on how to get more information about "resources" (like returned by !locks command) or even synchronization event objects shown by !process?

A. Unfortunately, events are very difficult to analyze as they do not have owners as critical sections, mutants and executive resources (!locks). Here’s one example with events as terminating wait chains:

http://www.dumpanalysis.org/blog/index.php/2008/11/07/crash-dump-analysis-patterns-part-42d/

Regarding ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required