The full transcript of Software Diagnostics Services training with 9 step-by-step exercises. Learn how to navigate through memory dump space and Windows data structures to perform memory forensics, troubleshoot and debug complex software incidents. The training uses a unique and innovative pattern-driven analysis approach to speed up the learning curve. It consists of practical step-by-step exercises using WinDbg to diagnose structural and behavioural patterns in Windows RT kernel and complete (physical) memory dumps. Additional topics include memory search, kernel linked list navigation, practical WinDbg scripting, registry, system variables and objects, device drivers and I/O, memory mapped and cached files content.
Prerequisites: Basic and intermediate level Windows memory dump analysis: ability to list processors, processes, threads, modules, apply symbols, and walk through stack traces.
Audience: Software developers, software technical support and escalation engineers, reverse and security research engineers, digital forensic analysts.
- Title: Advanced Windows RT Memory Dump Analysis, ARM Edition: Training Course Transcript and WinDbg Practice Exercises
- Authors: Dmitry Vostokov, Software Diagnostics Services
- Publisher: OpenTask (March 2014)
- Language: English
- Product Dimensions: 28.0 x 21.6
- Paperback: 190 pages
- ISBN-13: 978-1908043733
Table of Contents
Available in PDF format with $50 discount.
When you purchase the book you additionally get free Software Diagnostics Library membership with access to more than 200 cross-referenced patterns of memory dump analysis, their classification and more than 70 case studies.
Note: Another $50 discount is available for those who previously booked Advanced Windows Memory Dump Analysis training or purchased its book. Please use the contact form if you would like to buy the book with a discount.