Connect with us on Facebook and Linkedin

Book: Practical Foundations of Windows Debugging, Disassembling, Reversing

This training course is a combined and reformatted version of the two previous books Windows Debugging: Practical Foundations and x64 Windows Debugging: Practical Foundations. The new format makes it easy to switch between and compare x86 and x64 versions. The book also has a larger format similar to other training courses, punctuation and code highlighting improvements, the output and screenshots from the latest WinDbg 10, and consistently uses WinDbg (X86) for 32-bit examples and WinDbg (X64) for 64-bit examples.

The book contains two separate sets of chapters and corresponding illustrations. They are named Chapter x86.NN and Chapter x64.NN respectively. There is some repetition of content due to the shared nature of x64 and x86 platforms. Both sets of chapters can be read independently. We included x86 chapters because many Windows applications are still 32-bit and executed in 32-bit compatibility mode on x64 Windows systems.

This introductory training course can complement the more advanced course Accelerated Disassembly, Reconstruction and Reversing.

  • Title: Practical Foundations of Windows Debugging, Disassembling, Reversing: Training Course
  • Authors: Dmitry Vostokov, Software Diagnostics Institute
  • Publisher: OpenTask (October 2015)
  • Language: English
  • PDF: 350 pages
  • ISBN-13: 978-978-1908043948

Table of Contents

Purchase

We are now the authorized training provider!

We are appointed by Software Diagnostics Institute as the authorized training provider for pattern-oriented software diagnostics and associated subfields: http://www.dumpanalysis.org/authorized-training-providers

Software Diagnostics and Debugging Reference

New! Includes Encyclopedia of Pattern-Oriented Software Diagnostics.

Memory Dump Analysis Anthology contains revised, edited, cross-referenced, and thematically organized selected articles from Software Diagnostics Institute and Software Diagnostics Library (former Crash Dump Analysis blog) about software diagnostics, debugging, crash dump analysis, software trace and log analysis, malware analysis and memory forensics. Its 9 volumes in 11 books have more than 3,800 pages and among many topics include more than 320 memory analysis patterns (mostly for WinDbg Windows debugger with selected Mac OS X and Linux GDB variants), more than 70 WinDbg case studies, more than 130 general trace and log analysis patterns.

9 volumes in 11 books are now in the 2nd revision!

Tables of Contents and Indexes of WinDbg Commands from all volumes

Click on an individual volume to see its description and table of contents:

The print version also includes 3-volume supplement with selected anthology articles reprinted in full premium color (more than 500 pages with almost 400 color illustrations). Click on an individual volume to see its description and table of contents:

You can buy either the 9-volume PDF set plus 2 Encyclopedia books with 40% discount or 14-book set plus 2 Encyclopedia books in paperback format with 60% discount and trackable shipping included (shipped from OpenTask publisher, some restrictions may apply) or both with further discounts:

If you are only interested in Memory Dump Analysis Anthology volume set in PDF format please use this link.

Purchase

You also get free access to Software Diagnostics Library.

Note: We are not responsible for any loss or damage during shipment and delivery.

Memory Dump Analysis Anthology, Volume 8b

We are now distributors of Volume 8b of Memory Dump Analysis Anthology in PDF format:

Purchase

Complete 9-volume set in PDF format is also available with a discount.

Recorded Training Sessions

New! Historical video recordings of past training sessions corresponding to the following courses are now available:

Accelerated Windows Memory Dump Analysis, 3rd edition (8 hours)

Accelerated Windows Debugging3 (4 hours)

Accelerated .NET Memory Dump Analysis, 2nd edition (4 hours)

Accelerated Disassembly, Reconstruction and Reversing (4 hours)

Accelerated Windows Malware Analysis with Memory Dumps (4 hours)

The price of each set of recordings is 99 USD and they can be purchased independently of the corresponding training courses and training packs. Download links are sent in 24-48 hours after the purchase. When you purchase you also get free named Software Diagnostics Library membership with access to more than 300 cross-referenced patterns of memory dump analysis, their classification, and more than 70 case studies.

Purchase

Memory Dump Analysis Anthology, Volume 5

We are now distributors of Volume 5 of Memory Dump Analysis Anthology in PDF format:

Purchase

Complete 9-volume set in PDF format is also available with a discount.

Memory Dump Analysis Anthology, Volume 4

We are now distributors of Volume 4 of Memory Dump Analysis Anthology in PDF format:

Purchase

Complete 9-volume set in PDF format is also available with a discount.

Platform-Independent Crash Dump Analysis Training Pack

New! Now includes Practical Foundations of Windows Debugging, Disassembling, Reversing PDF book.

Learn how to analyze application crashes and freezes, navigate through process memory dump space and diagnose corruption, memory leaks, CPU spikes, blocked threads, deadlocks, wait chains and much more. We use a unique and innovative platform-independent pattern-oriented analysis approach to speed up the learning curve. The training pack consists of practical step-by-step exercises using popular debuggers WinDbg, GDB, and LLDB highlighting dozens of memory analysis patterns diagnosed in 64-bit process memory dumps from Windows, Mac OS X and Linux platforms. The training pack also includes source code for modeling applications, a catalogue of relevant patterns from Software Diagnostics Institute, an overview of relevant similarities and differences between Windows, Mac OS X and Linux user space memory dump analysis, and Windows kernel and physical memory space analysis exercises necessary for learning pattern diagnosis of complex application and service inter-process communication problems.

This comprehensive training pack for software technical support engineers, system administrators, DevOps, software developers and testers features:

  • 3 platforms (x86/x64 Windows, x64 Mac OS X, x64 Linux)
  • 3 debuggers (WinDbg, GDB, LLDB)
  • 4 training courses
  • 14 books (17 in print version)
  • 90 hands-on exercises
  • 170 slides with comments
  • 100 questions and answers
  • 1,800 pages of training books
  • 3,700 pages of reference materials (4,100 in print version)

This offer includes training courses and access to the vast collection of patterns and case studies:

  1. Accelerated Windows Memory Dump Analysis, 4th edition
  2. Accelerated Mac OS X Core Dump Analysis, 2nd edition
  3. Accelerated Linux Core Dump Analysis
  4. Practical Foundations of Windows Debugging, Disassembling, Reversing PDF book
  5. Access to Software Diagnostics Library
  6. Memory Dump Analysis Anthology volume set

You can buy either in PDF or paperback format with trackable shipping included (shipped from OpenTask publisher, some restrictions may apply) or both with further discounts:

Purchase

Note: We are not responsible for any loss or damage caused during shipment and delivery.

Memory Dump Analysis Anthology, Volume 3

We are now distributors of Volume 3 of Memory Dump Analysis Anthology in PDF format:

Purchase

Complete 9-volume set in PDF format is also available with a discount.

Memory Dump Analysis Anthology, Volume 2

We are now distributors of Volume 2 of Memory Dump Analysis Anthology in PDF format:

Purchase

Complete 9-volume set in PDF format is also available with a discount.

Training Courses and Training Packs Upgrade

You can now upgrade previously purchased individual training courses to training packs, and training packs to bigger training packs by simply paying the difference. For example,

Accelerated Windows Memory Dump Analysis ->
    Windows Crash Dump Analysis Training Pack ->
        Windows Complete Memory Dump Analysis Training Pack ->
            Enterprise Windows Software Diagnostics and Debugging Pack

Revisions of Memory Dump Analysis Anthology Volumes

Volume 1 is now in its 3rd revision. The main changes since the 2nd revision are readability and punctuation improvements. Content is the same. If you purchased Volume 1 from us in PDF format separately or as a part of training courses, training packs, and reference sets before the 22nd of March, 2015, please use the contact form to request the free update.

Volume 2 is now in its 3rd revision. The main changes since the 2nd revision are readability and punctuation improvements. Content is the same except that some web links were updated. If you purchased Volume 2 from us in PDF format separately or as a part of training courses, training packs, and reference sets before the 20th of April 2015, please use the contact form to request the free update.

Volume 3 of Memory Dump Analysis Anthology is now in its 2nd revision. The main changes are readability and punctuation improvements. Content is the same except some updated web links. If you purchased Volume 3 from us in PDF format separately or as a part of training courses, training packs, and reference sets before the 29th of April 2015, please use the contact form to request the free update.

Volume 4 of Memory Dump Analysis Anthology is now in its 2nd revision. The main changes are readability and punctuation improvements. Content is the same except some updated web links. If you purchased Volume 4 from us in PDF format separately or as a part of training courses, training packs, and reference sets before the 12th of June 2015, please use the contact form to request the free update.

Volume 5 of Memory Dump Analysis Anthology is now in its 2nd revision. The main changes are readability and punctuation improvements. Content is the same except some updated web links. If you purchased Volume 5 from us in PDF format separately or as a part of training courses, training packs, and reference sets before the 21st of June 2015, please use the contact form to request the free update.

Volume 6 of Memory Dump Analysis Anthology is now in its 2nd revision. The main changes are readability and punctuation improvements. Content is the same except some updated web links. If you purchased Volume 6 from us in PDF format separately or as a part of training courses, training packs, and reference sets before the 17th of July 2015, please use the contact form to request the free update.

Volume 7 of Memory Dump Analysis Anthology is now in its 2nd revision. The main changes are readability and punctuation improvements. Content is the same except some updated web links. If you purchased Volume 7 from us in PDF format separately or as a part of training courses, training packs, and reference sets before the 24th of July 2015, please use the contact form to request the free update.

Volume 8a of Memory Dump Analysis Anthology is now in its 2nd revision. The main changes are readability and punctuation improvements. Content is the same. If you purchased Volume 8a from us in PDF format separately or as a part of training courses, training packs, and reference sets before the 10th of July 2015, please use the contact form to request the free update.

Windows Complete Memory Dump Analysis Training Pack

New! The PDF version pack now includes a complimentary EPUB version of Accelerated Windows Memory Dump Analysis, Fourth Edition

This comprehensive training teaches the analysis of all memory spaces for patterns of abnormal software behavior in process, kernel, and complete (physical) memory dumps:

The pack features:

  • Both x86 and x64 Windows versions
  • Both kernel and user memory spaces
  • Both managed, unmanaged, and native code
  • 4 training courses
  • 16 books (19 in print version)
  • 70 hands-on exercises
  • 140 slides with comments
  • 130 questions and answers
  • 1,700 pages of training books
  • 4,800 pages of reference materials (5,200 in print version)

This offer includes training courses, pattern encyclopedia, and access to the vast collection of patterns and case studies:

  1. Accelerated Windows Memory Dump Analysis, 4th edition
  2. Accelerated .NET Memory Dump Analysis, 2nd edition
  3. Advanced Windows Memory Dump Analysis with Data Structures, 2nd edition
  4. Practical Foundations of Windows Debugging, Disassembling, Reversing
  5. Access to Software Diagnostics Library
  6. Memory Dump Analysis Anthology volume set and Encyclopedia of Crash Dump Analysis Patterns

You can buy either in PDF or paperback format with trackable shipping included (shipped from OpenTask publisher, some restrictions may apply) or both with further discounts:

Purchase

Note: We are not responsible for any loss or damage caused during shipment and delivery.

Encyclopedia of Pattern-Oriented Software Diagnostics

This is a comprehensive, alphabetically organized multi-volume pattern language reference for software technical support engineers, system and network administrators, software developers and testers, security researchers and reverse engineers, digital forensics and malware analysts. Currently, it consists of the two books in PDF format with the total of 1,250 pages.

This offer also includes online named access to Software Diagnostics Library:

  1. Encyclopedia of Crash Dump Analysis Patterns
  2. Software Trace and Log Analysis: A Pattern Reference
  3. Access to Software Diagnostics Library

Purchase

Note: 50% discount is available for those who previously bought 7- or 8-volume Software Diagnostics and Debugging Reference. Please use the contact form if you would like to buy with a discount.

Trace and Log Analysis Training Pack

This comprehensive pattern-oriented trace and log analysis training for software technical support engineers, system and network administrators, software developers and testers, digital forensics and malware analysts features:

  • 17 books (20 in print version)
  • 300 slides with comments
  • 3,700 pages of reference materials (4,100 in print version)

This offer includes a training course with recording, seminar transcripts, a pattern reference, and online access to the vast collection of patterns and case studies:

  1. Accelerated Windows Software Trace Analysis
  2. Software Trace and Log Analysis: A Pattern Reference
  3. Software Trace and Memory Dump Analysis: Patterns, Tools, Processes and Best Practices
  4. Software Narratology: An Introduction to the Applied Science of Software Stories
  5. Malware Narratives: An Introduction
  6. Pattern-Oriented Network Trace Analysis
  7. Mobile Software Diagnostics: An Introduction
  8. Access to Software Diagnostics Library
  9. Memory Dump Analysis Anthology volume set

You can buy either in PDF or paperback format with trackable shipping included (shipped from OpenTask publisher, some restrictions may apply) or both with further discounts:

Purchase

Note: We are not responsible for any loss or damage caused during shipment and delivery.

Pattern Diagnostics Logo

Also available in a white background version.

Free Sample Exercise eBook

We are happy to announce the release of Pattern-Oriented Software Diagnostics, Debugging, Malware Analysis, Reversing: Sample Training Exercises eBook which is free to download and share. It contains 9 exercises from various training courses.

Syndicate content