Table of Contents

Table of Contents

Preliminaries

x86-x64 processor architecture

Interrupts

Windows architecture and components

Dump Origins

Dump Collection

Basic Analysis

Quick WinDbg tour

Problem identification

Process dumps

Kernel dumps

Complete dumps

Minidumps

Advanced Analysis

Stack reconstruction

Construct identification

Component identification

Automation

Scripts

Checklists

Databases

Patterns

Classification

Catalog

System

Architectural

Implementation

Tool-specific

Management

VERSION steps

SMART Process