Skip to content

WinDbg

Debugging Symbols

  • File > Symbol File Path
  • Symbol files allows referencing instead of only using addresses
    • Internal functions
    • Structures
    • Global variables

Cheatsheet

.reaload /f                 Reload added symbols

u [Range|Address]           Unassemble specific range/address   "u kernel32!GetCurrentThread"

d{a|b|c|d|D|f|p|q|u|w|W}    Display memory
dd esp L4                   Control displayed data length with L    
dd poi(esp)                 Display memory on pointer location      
dt ntdll!_TEB               Display type
dt -r ntdll!_TEB @$teb      Recursively display nested structures
    dt ntdll!_TEB @$teb ThreadLocalStoragePointer   Display specific fields
?? sizeof(ntdll!_TEB)       Get size of structure

e{b|d|D|f|p|q|w}            Enter values - change memory
ed esp 41414141
ea esp "Hello"

s -d 0 L?80000000 41414141  Search (s <type> <searching address> <LENGTH> <PATTERN>)
  -d  DWORD
  -a ASCII

r                           Show registers
    <register>              e.g. r eax
    <register>=<value>      Write value into register

bp kernel32!WriteFile       Break at specific API call

bl                          List breakpoints
bd/be/bc                    Disable/Enable/Clear breakpoints
bu                          Breakpoint in unresolved function which is later loaded
ba e1 kernel32!WriteFile   Break on (e)xecute/(r)ead/(w)rite of section - 1=size in byted

p/t/pt/ph                   Step over/Into/Next Return/Next branching

lm                          List modules
    lm m kernel*            Filter modules by name
x kernelbase!CreateProc*    Examine symbols

0n/0y                       Format hex format to decimal/binary
.formats 41414141           Show all formats for a value

!teb                        Thread related pointer such as ExceptionList pointer
!exchain                    List current threat exception handlers
k                           Inspect callstack
  • Breakpoint-based actions
bp kernel32!WriteFile ".if (poi(esp + 0x0C) != 4) {gc} .else {.printf \"The number of bytes written is 4\";.echo;}"
bp kernel32!WriteFile ".if (poi(esp + 0x0C) != 4) {gc} .else {.printf \"The number of bytes written is 4\";.echo;}"
  • Calculate
? 77269bc0  - 77231430
? 77269bc0 >> 18
  • Pseudo Registers
    • $t0 to $t19

Extensions

.load narly
.nmod           List loaded modules and security

Resources

https://learn.microsoft.com/en-us/windows-hardware/drivers/debuggercmds/d--da--db--dc--dd--dd--df--dp--dq--du--dw--dw--dyb--dyd--display-memor http://windbg.info/doc/1-common-cmds.html