Kernel debugger essentials
.cache forcedecodeuser or .thread /p to translate PTEs to physical addresses.
.process # | .thread to switch context to a specific process
!process 0 0 to get list of processes.
and of course, !analyze -v to get a quick summary of a crash dump.
Monday, May 08, 2006
Subscribe to:
Post Comments (Atom)

0 comments:
Post a Comment