WinDbg Commands for Live Binary Analysis
Essential commands used to inspect buffers, catch encryption, and trace function behavior in WinDbg during disassembly/reverse engineering.
Inspecting Memory
db eax L edi ; dump bytes at address eax, length edi
db= dump byteseax= start addressL= length keywordedi= number of bytes to show
Variations:
- dd <addr> — dump as 32-bit dwords (good for lengths, pointers)
- dc <addr> — dump bytes with ASCII sidecar
- da <addr> — dump null-terminated ASCII string
Dereferencing Pointers
dd poi(ebp-8) ; read pointer at ebp-8, then dump dwords there
poi(...)= pointer-of / dereference- Useful when a local variable holds the address of a buffer
Catching Encryption or Modification
ba w1 eax ; break when anything writes 1 byte at eax
ba= break on accessw= write access1= size in bytes (can use 2, 4, 8)- Set this right after a buffer is prepared to find the function that encrypts or modifies it
Call Stack and Control Flow
k ; show call stack
kv ; verbose call stack with arguments
r ; show registers
p ; step over
t ; step into
g ; go / continue
Example Session Pattern
- Break before
send()call. db eax L edito see plaintext being transmitted.ba w1 eaxto catch the next write to that buffer.gto continue; debugger stops inside the encryption routine.kvto see which function called the encryption routine.