Accelerated Windows Memory Dump Analysis, Sixth Edition

Slides from Part 1 Slides from Part 2

The full-color transcript of Software Diagnostics Services training sessions with 36 step-by-step exercises, notes, source code of specially created modeling applications, and more than 120 questions and answers. Covers more than 80 crash dump analysis patterns from x64 process, kernel, and complete (physical) memory dumps. Learn how to analyze application, service and system crashes and freezes, navigate through memory dump space, and diagnose heap corruption, memory leaks, CPU spikes, blocked threads, deadlocks, wait chains, and much more. The training uses a unique and innovative pattern-oriented analysis approach developed by Software Diagnostics Institute to speed up the learning curve. Prerequisites: Basic Windows troubleshooting. Audience: Software technical support and escalation engineers, system administrators, security researchers, reverse engineers, malware and memory forensics analysts, software developers, and quality assurance engineers. The 6th edition was fully reworked for the latest WinDbg version and includes additional Windows 11 memory dumps, relevant x64 assembly language review, a Rust memory dump analysis example, and a BSOD analysis pattern strategy outline.

The course consists of two parts:

  • Title: Accelerated Windows Memory Dump Analysis, Sixth Edition, Part 1, Process User Space: Training Course Transcript and WinDbg Practice Exercises with Notes
  • Authors: Dmitry Vostokov, Software Diagnostics Services
  • Publisher: OpenTask (August 2023)
  • Language: English
  • PDF: 354 pages
  • ISBN-13: 978-1912636921
  • Table of Contents and Sample Exercise
  • Title: Accelerated Windows Memory Dump Analysis, Sixth Edition, Part 2, Kernel and Complete Spaces: Training Course Transcript and WinDbg Practice Exercises with Notes
  • Authors: Dmitry Vostokov, Software Diagnostics Services
  • Publisher: OpenTask (August 2023)
  • Language: English
  • PDF: 388 pages
  • ISBN-13: 978-1912636938
  • Table of Contents and Sample Exercise

When you purchase the PDF or printed books, you additionally get free named Software Diagnostics Library membership with access to more than 380 cross-referenced patterns of memory dump analysis, their classification, and more than 70 case studies.

The training course also includes the recording of the training sessions and Practical Foundations of Windows Debugging, Disassembling, Reversing, Second Edition book.

There is an option to buy 15 volumes of Memory Dump Analysis Anthology in PDF format together with the course.

Available in either PDF or ultra-premium color paperback or both. The printed paperback course also includes the printed Practical Foundations book and trackable shipping to most countries of North America and Europe. If your country's trackable shipping is expensive, you will be contacted with additional payment information. The order is shipped in 5 working days. The full-color Accelerated book can be personalized with a unique CID with the possibility to print a name on a full-color certificate as a first book page.

Type and speed (links sent in 24 hours)