> For the complete documentation index, see [llms.txt](https://alham-rizvi.gitbook.io/alhamrizvi/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://alham-rizvi.gitbook.io/alhamrizvi/exploit-development/cheatsheets/windbg.md).

# WinDbg Cheatsheet — Exploit Development

## Setup & Configuration

```
.symfix                          # Set symbol path to Microsoft symbol server
.symfix+ C:\symbols              # Add local cache
.reload                          # Reload symbols
.sympath                         # Show current symbol path
.reload /f ntdll.dll             # Force reload specific module symbols
!sym noisy                       # Verbose symbol loading (debug missing syms)
!sym quiet                       # Suppress symbol noise

.load pykd.dll                   # Load pykd extension (Python scripting)
.load mona.py                    # Load mona.py (via pykd)
!py mona modules                 # Run mona command after loading
```

## Execution Control

```
g                                # Go (continue execution)
p                                # Step over (source level)
t                                # Step into (source level)
pa <addr>                        # Step over until address
ta <addr>                        # Step into until address
gu                               # Step out (go up — execute until return)
gh                               # Go with exception handled
gn                               # Go with exception not handled

q                                # Quit debugger
qd                               # Detach and quit
```

## Breakpoints

```
bp <addr>                        # Set breakpoint at address
bp <module>!<func>               # Break on function (e.g. bp kernel32!VirtualAlloc)
bu <module>!<func>               # Unresolved breakpoint (survives module reloads)
bm <pattern>                     # Break on all matching symbols (wildcards ok)
ba e1 <addr>                     # Hardware exec breakpoint (1-byte, execute)
ba r4 <addr>                     # Hardware read/write breakpoint (4-byte)
ba w4 <addr>                     # Hardware write breakpoint (4-byte)
bc *                             # Clear all breakpoints
bc <id>                          # Clear breakpoint by ID
bd <id>                          # Disable breakpoint
be <id>                          # Enable breakpoint
bl                               # List all breakpoints

bp <addr> "r; g"                 # Conditional: dump regs then continue
bp <addr> ".if (poi(esp)==0x41414141) {} .else {gc}"   # Conditional breakpoint
```

***

## Registers

```
r                                # Show all registers
r eax                            # Show single register
r eax=0x41414141                 # Set register value
r eip=<addr>                     # Redirect execution

r @eax                           # Register with @ prefix (unambiguous)
r $ip                            # Instruction pointer (arch-neutral alias)
r $sp                            # Stack pointer alias
```

## Memory Examination

```
dd <addr>                        # Display DWORDs (4-byte, hex)
dq <addr>                        # Display QWORDs (8-byte, hex) — x64
db <addr>                        # Display bytes + ASCII
da <addr>                        # Display ASCII string
du <addr>                        # Display Unicode string
dW <addr>                        # Display WORDs (2-byte)
dp <addr>                        # Display pointer-sized values

dd esp L10                       # Display 16 DWORDs from ESP
dd <addr> L<n>                   # L<n> = length in units (not bytes)

dds esp                          # Display stack as DWORDs with symbols
dqs rsp                          # Display x64 stack as QWORDs with symbols
dps <addr> L<n>                  # Display pointer-sized with symbol resolution
```

## Memory Writing

```
ed <addr> <value>                # Edit DWORD at address
eq <addr> <value>                # Edit QWORD
eb <addr> <bytes>                # Edit bytes (space-separated hex)
ea <addr> "string"               # Write ASCII string
eu <addr> "string"               # Write Unicode string

f <addr> L<n> <pattern>         # Fill memory (e.g. f esp L100 41)
```

## Memory Search

```
s -b <start> L<len> <bytes>      # Search for byte pattern
s -d <start> L<len> <dword>      # Search for DWORD value
s -q <start> L<len> <qword>      # Search for QWORD
s -a <start> L<len> "string"     # Search for ASCII string
s -u <start> L<len> "string"     # Search for Unicode string

s -b 0x0 L?0x7fffffff 90 90 90   # Search entire userland for NOP sled
s -b <mod_start> L<mod_size> ff e4   # Search module for JMP ESP (ff e4)
```

## Disassembly

```
u <addr>                         # Unassemble (8 instructions default)
u <addr> L<n>                    # Unassemble n instructions
uf <addr>                        # Unassemble entire function
ub <addr>                        # Unassemble backwards
u eip                            # Disassemble at current instruction
u poi(esp)                       # Disassemble at address pointed to by ESP
```

## Stack & Call Stack

```
k                                # Stack trace
kb                               # Stack trace with first 3 parameters
kv                               # Stack trace with FPO and frame info
kn                               # Stack trace with frame numbers
kd                               # Raw stack dump
.frame <n>                       # Switch to frame n
.frame /r <n>                    # Switch to frame n, show registers

dv                               # Display local variables (current frame)
dv /t                            # Display locals with type info
dt <type> <addr>                 # Display type structure at address
```

## Modules & Symbols

```
lm                               # List loaded modules
lm m <pattern>                   # List modules matching pattern (e.g. lm m ntdll)
lmf m <pattern>                  # List modules with full path
!lmi <module>                    # Module info (base, size, timestamp)

x <module>!<symbol>              # Examine symbol address
x ntdll!*alloc*                  # Find all alloc-related exports in ntdll
x /a kernel32!*                  # List all kernel32 exports by address

ln <addr>                        # List nearest symbols to address
```

## Exploit Development — Key Commands

### Finding ROP Gadgets / JMP ESP

```
# Search for JMP ESP (ff e4) across all executable modules
s -b 0x00000000 L?0x7fffffff ff e4

# Search for CALL ESP (ff d4)
s -b 0x00000000 L?0x7fffffff ff d4

# Search for specific gadgets (e.g. POP EAX; RET = 58 c3)
s -b <module_base> L<module_size> 58 c3

# Use !address to find executable ranges first
!address -f:MEM_COMMIT+PAGE_EXECUTE_READ
```

### Checking SEH Chain

```
!exchain                         # Show SEH chain
!exchain -v                      # Verbose SEH chain
dt _EXCEPTION_REGISTRATION_RECORD @$teb+0   # Manual SEH inspection
dd fs:[0]                        # SEH chain pointer (x86 TEB)
```

### Heap Exploitation

```
!heap -h                         # Heap help
!heap                            # List all heaps
!heap -s                         # Heap summary statistics
!heap -a <heap_handle>           # Full heap analysis
!heap -b alloc                   # Break on heap allocation
!heap -b free                    # Break on heap free
!heap -x <addr>                  # Find which heap chunk owns address
!heap -p -a <addr>               # Heap entry at address (with allocation stack)
!heap -p -h <handle>             # All allocations in heap

# Low Fragmentation Heap (LFH)
!heap -l                         # List LFH info
```

### Format String / Memory Layout

```
dt nt!_TEB                       # Thread Environment Block layout
dt nt!_PEB                       # Process Environment Block layout
dt nt!_PEB @$peb                 # PEB at actual address
!teb                             # TEB summary
!peb                             # PEB summary

dt nt!_HEAP                      # Heap structure
dt nt!_HEAP_ENTRY                # Heap chunk header structure
```

### Stack Cookie / GS Bypass Research

```
# Find __security_cookie in a module
x <module>!__security_cookie
dd <module>!__security_cookie L1

# Find SafeSEH table
!dh -f <module>                  # DLL headers — look for SafeSEH flag
```

### ASLR / Rebase Analysis

```
!address <addr>                  # Region info: base, size, protect flags
!address -summary                # Summary of all regions
lm va <module>                   # Show VA range of module (check for ASLR slide)

# Find non-ASLR modules (loaded at fixed base)
!lmi <module>                    # Check "Load address" vs preferred
```

### DEP / NX Analysis

```
!vprot <addr>                    # Virtual protect flags for region
!address <addr>                  # Shows PAGE_EXECUTE_* flags

# Check DEP policy for process
!exploitable                     # If extension loaded — checks exploitability
```

## Crash Triage & Exploitability

```
!analyze -v                      # Auto-analyze crash (verbose)
!analyze -show                   # Show last analysis
!exploitable                     # Classify crash exploitability (requires ext)

.lastevent                       # Last debug event (exception code + address)
.exr -1                          # Last exception record
.ecxr                            # Switch context to last exception

# Exception codes
# 0xC0000005 = Access Violation
# 0xC00000FD = Stack Overflow
# 0x80000003 = Breakpoint
# 0xC0000094 = Integer Divide by Zero
```

## Pattern Cyclic (with mona.py or manual)

```
# With mona.py (via pykd)
!py mona pattern_create 2000     # Create 2000-byte cyclic pattern
!py mona pattern_offset eip      # Find EIP offset from pattern
!py mona pattern_offset <value>  # Offset of any value in pattern

# Manual offset search — after crash, read EIP/RSP
r eip                            # Get EIP value after crash
```

## WinDbg Scripting

```
# Conditional breakpoint with logging
bp <addr> "dd esp L4; g"

# Log function args on each call
bp kernel32!VirtualAlloc "dd esp+4 L3; g"

# Run script file
$$>< script.txt                  # Execute script (with args)
$><  script.txt                  # Execute script (no args expansion)

# Pseudo-registers
$exentry                         # Entry point of process
$peb                             # PEB address
$teb                             # TEB address
$retreg                          # Return value register (EAX/RAX)
$ip                              # Instruction pointer
$sp                              # Stack pointer
$ra                              # Return address

# Loop example — dump 10 stack values
.for (r $t0=0; $t0<10; r $t0=$t0+1) { dd esp+($t0*4) L1 }
```

## Useful Extensions

```
!load <ext.dll>                  # Load WinDbg extension

# Built-in
!address                         # Virtual memory regions
!handle                          # Handle table
!locks                           # Critical section locks
!threads                         # Thread list
~*kb                             # Stack trace all threads
~<n>s                            # Switch to thread n
~*e !clrstack                    # CLR stack all threads (managed)

# Common third-party
!py mona <cmd>                   # mona.py — ROP, pattern, module analysis
!exploitable                     # msec.dll — crash severity rating
```

## x64 Quick Reference

```
# Registers: RAX RBX RCX RDX RSI RDI RSP RBP R8–R15
# First 4 args (Windows x64): RCX, RDX, R8, R9

r rax, rbx, rcx, rdx            # Show x64 registers
dq rsp L8                        # 64-bit stack
dqs rsp                          # Stack with symbol names
u rip                            # Disassemble at current instruction

# Shadow space: 32 bytes above return address reserved for callee
# RSP must be 16-byte aligned at CALL instruction
```

## Quick Command Reference Card

| Goal               | Command                       |
| ------------------ | ----------------------------- |
| Set a breakpoint   | `bp module!func`              |
| Hardware exec BP   | `ba e1 <addr>`                |
| Show registers     | `r`                           |
| Dump stack         | `dds esp`                     |
| Disassemble        | `uf <addr>`                   |
| Search bytes       | `s -b 0 L?0x7fffffff <bytes>` |
| SEH chain          | `!exchain`                    |
| Heap analysis      | `!heap -a <handle>`           |
| Module list        | `lm`                          |
| Crash analysis     | `!analyze -v`                 |
| Symbol lookup      | `x module!*pattern*`          |
| Find nearest sym   | `ln <addr>`                   |
| Memory region info | `!address <addr>`             |
| Step over          | `p`                           |
| Step into          | `t`                           |
| Step out           | `gu`                          |
| Continue           | `g`                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://alham-rizvi.gitbook.io/alhamrizvi/exploit-development/cheatsheets/windbg.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
