WinDbg Commands for Live Binary Analysis

Essential commands used to inspect buffers, catch encryption, and trace function behavior in WinDbg during disassembly/reverse engineering.

Inspecting Memory

db eax L edi        ; dump bytes at address eax, length edi
  • db = dump bytes
  • eax = start address
  • L = length keyword
  • edi = number of bytes to show

Variations:
- dd <addr> — dump as 32-bit dwords (good for lengths, pointers)
- dc <addr> — dump bytes with ASCII sidecar
- da <addr> — dump null-terminated ASCII string

Dereferencing Pointers

dd poi(ebp-8)       ; read pointer at ebp-8, then dump dwords there
  • poi(...) = pointer-of / dereference
  • Useful when a local variable holds the address of a buffer

Catching Encryption or Modification

ba w1 eax           ; break when anything writes 1 byte at eax
  • ba = break on access
  • w = write access
  • 1 = size in bytes (can use 2, 4, 8)
  • Set this right after a buffer is prepared to find the function that encrypts or modifies it

Call Stack and Control Flow

k                   ; show call stack
kv                  ; verbose call stack with arguments
r                   ; show registers
p                   ; step over
t                   ; step into
g                   ; go / continue

Example Session Pattern

  1. Break before send() call.
  2. db eax L edi to see plaintext being transmitted.
  3. ba w1 eax to catch the next write to that buffer.
  4. g to continue; debugger stops inside the encryption routine.
  5. kv to see which function called the encryption routine.