<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Defrag Tools: #22 - WinDbg - Memory Kernel Mode</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode/RSS"></atom:link>
	<image>
		<url>http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22_220.jpg</url>
		<title>Channel 9 - Defrag Tools: #22 - WinDbg - Memory Kernel Mode</title>
		<link></link>
	</image>
	<description>In this episode of Defrag Tools, Andrew Richards, Chad Beeder and Larry Larsen continue looking at the Debugging Tools for Windows (in particular WinDbg). WinDbg is a debugger that supports user mode debugging of a process, or kernel mode debugging of a computer. This installment goes over the commands used to show the memory used in a kernel mode debug session. We cover these commands: !vm !vm 1 !memusage 8 !poolused 2 !poolused 4 !poolfind &amp;lt;tag&amp;gt; !pool &amp;lt;addr&amp;gt; !pool &amp;lt;addr&amp;gt; 2 !pte Make sure you watch Defrag Tools Episode #1 for instructions on how to get the Debugging Tools for Windows and how to set the required environment variables for symbols and source code resolution. Resources:Microsoft Windows SDK for Windows 7 and .NET Framework 4 Sysinternals LiveKDSysinternals RAMMap Timeline:[00:45] - Sysinternals LiveKD debug of the machine[01:47] - Virtual Memory summary (!vm 1)[05:10] - Sysinternals LiveKD live kernel dump (livekd.exe -m -o kernel.dmp)[09:30] - Sysinternals RAMMap[11:10] - Memory List summary (!memusage 8)[16:15] - Pool Usage by Non-Paged Pool (!poolused 2)[20:16] - Pool Tags (c:\debuggers\triage\pooltag.txt)[28:06] - Pool Usage by Paged Pool (!poolused 4)[29:27] - Pool issues lead to Bugchecks[34:00] - Find Pool by Address&amp;nbsp;(!pool &amp;lt;addr&amp;gt;)[36:05] - Find Pool by Tag (!poolfind &amp;lt;tag&amp;gt;)[40:30] - Page Table Entry (PTE) and Page Frame Number (PFN) (!pte &amp;lt;addr&amp;gt;)[42:45] - Sometimes it is a physical hardware failure </description>
	<link></link>
	<language>en</language>
	<pubDate>Tue, 21 May 2013 10:50:12 GMT</pubDate>
	<lastBuildDate>Tue, 21 May 2013 10:50:12 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Defrag Tools: #22 - WinDbg - Memory Kernel Mode</title>
		<description>
			<![CDATA[<p>The video seems to bug out at 31:57.&nbsp; Is anyone else having this issue or is it just me?</p><p>posted by JohnLudlow</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634932657642626477</link>
		<pubDate>Tue, 08 Jan 2013 18:16:04 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634932657642626477</guid>
		<dc:creator>JohnLudlow</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #22 - WinDbg - Memory Kernel Mode</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634932657642626477">JohnLudlow</a>: what's happening with your video exactly?&nbsp;</p><p>posted by golnazal</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634932900411296131</link>
		<pubDate>Wed, 09 Jan 2013 01:00:41 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634932900411296131</guid>
		<dc:creator>golnazal</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #22 - WinDbg - Memory Kernel Mode</title>
		<description>
			<![CDATA[<p>Happy New Year!!!&nbsp;</p><p>Dudes I love this series its totally awesome... I feel you guy's are providing a great learning outlet especially for a beginner like myself.&nbsp;However at times the show gets hi jacked and it never gets back on course. I felt the past two episodes could have been a bit more linear and detailed.</p><p>keep up the good work dudes.</p><p>posted by dcrearer</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634933022862863135</link>
		<pubDate>Wed, 09 Jan 2013 04:24:46 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634933022862863135</guid>
		<dc:creator>dcrearer</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #22 - WinDbg - Memory Kernel Mode</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634933022862863135">dcrearer</a>:&nbsp; Send us an email at <a href="mailto:defragtools@microsoft.com">defragtools@microsoft.com</a> to explain what you exactly mean. We'd really like to hear your feedback in detail.</p><p>Since&nbsp;we are making up the content (live) as we go to air, we may get off track from time-to-time. When we do, call us on it and we will revisit the episode.</p><p>posted by windev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634933062989991133</link>
		<pubDate>Wed, 09 Jan 2013 05:31:38 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c634933062989991133</guid>
		<dc:creator>windev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #22 - WinDbg - Memory Kernel Mode</title>
		<description>
			<![CDATA[Great series, very beneficial for the forensic troubleshooting connoisseur.<br><br>Btw, concerning the &#39;bad&#39; pages mentioned in &#33;memusage, this value is typically not an accurate representation of actual bad pages. Pavel Lebedinsky, SDET at Microsoft, commented on this at the blog below&#58;<br><br>http&#58;&#47;&#47;analyze-v.com&#47;&#63;p&#61;558&#35;comments<br><br><p>posted by igarvin</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c635006900398829815</link>
		<pubDate>Thu, 04 Apr 2013 16:33:59 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#c635006900398829815</guid>
		<dc:creator>igarvin</dc:creator>
	</item>
</channel>
</rss>