Extended Windows Memory Dump Analysis - (Windows Internals Supplements) 2nd Edition (Paperback)
About this item
Highlights
- The book contains the full Software Diagnostics Services training transcript with 25 hands-on exercises.
- Author(s): Dmitry Vostokov & Software Diagnostics Services & Dublin School of Security
- 364 Pages
- Computers + Internet, Programming Languages
- Series Name: Windows Internals Supplements
Description
About the Book
The book contains the full Software Diagnostics Services training transcript with 25 hands-on exercises. This training course extends the pattern-oriented analysis introduced in the Accelerated Windows Memory Dump Analysis training books.
Book Synopsis
The book contains the full Software Diagnostics Services training transcript with 25 hands-on exercises. This training course extends pattern-oriented analysis introduced in Accelerated Windows Memory Dump Analysis, Accelerated .NET Core Memory Dump Analysis, and Advanced Windows Memory Dump Analysis with Data Structures courses with:
- Surveying the current landscape of WinDbg extensions with analysis pattern mappings
- Writing WinDbg extensions in C, C++, and Rust (new)
- Connecting WinDbg to NoSQL databases
- Connecting WinDbg to streaming and log processing platforms
- Querying and visualizing WinDbg output data
- Using Data Science, Machine Learning, and Gen AI for diagnostics and postmortem debugging (new)
The new edition of the training updates existing exercises and includes new ones.
Prerequisites: Working knowledge of WinDbg. Working knowledge of C, C++, or Rust is optional (required only for some exercises). Other concepts are explained when necessary.
Audience: Software developers, software maintenance engineers, escalation engineers, quality assurance engineers, security and vulnerability researchers, malware and memory forensics analysts who want to build memory analysis pipelines.