Connect with us on Facebook and Linkedin

Book: Advanced Windows RT Memory Dump Analysis, ARM Edition

The full transcript of Software Diagnostics Services training with 9 step-by-step exercises. Learn how to navigate through memory dump space and Windows data structures to perform memory forensics, troubleshoot and debug complex software incidents. The training uses a unique and innovative pattern-driven analysis approach to speed up the learning curve. It consists of practical step-by-step exercises using WinDbg to diagnose structural and behavioural patterns in Windows RT kernel and complete (physical) memory dumps. Additional topics include memory search, kernel linked list navigation, practical WinDbg scripting, registry, system variables and objects, device drivers and I/O, memory mapped and cached files content.

Prerequisites: Basic and intermediate level Windows memory dump analysis: ability to list processors, processes, threads, modules, apply symbols, and walk through stack traces.

Audience: Software developers, software technical support and escalation engineers, reverse and security research engineers, digital forensic analysts.

  • Title: Advanced Windows RT Memory Dump Analysis, ARM Edition: Training Course Transcript and WinDbg Practice Exercises
  • Authors: Dmitry Vostokov, Software Diagnostics Services
  • Publisher: OpenTask (March 2014)
  • Language: English
  • PDF: 190 pages
  • ISBN-13: 978-1908043733

Table of Contents

When you purchase the PDF book you additionally get free named Software Diagnostics Library membership with access to more than 300 cross-referenced patterns of memory dump analysis, their classification, and more than 70 case studies. There is an option to buy 9 volumes of Memory Dump Analysis Anthology in PDF format (retail price $170) together with the course.