WinDbg Stack Inspection Commands

Use these commands to inspect values that have been pushed onto the stack, especially right before a function call.

Core command

dd esp L2
Part Meaning
dd dump dwords — display 32-bit values
esp start at the address held by ESP (top of stack)
L2 show 2 dwords

On x86, push writes a 4-byte value to [esp] and decrements ESP by 4. So immediately after a push, dd esp L1 shows the value that was just pushed.

Common variants

Command Purpose
dd esp L4 dump 4 dwords from top of stack
da esp dump ASCII string at top of stack
du esp dump Unicode string at top of stack
dp esp L3 pointer-sized dump (works on x86 and x64)
dps esp L10 dump pointers with symbol resolution
dpp esp L5 dump pointer contents (dereferences each pointer)

64-bit note

On x64 the first four integer/pointer arguments are passed in registers (RCX, RDX, R8, R9), not on the stack. Additional arguments are at [rsp+0x20], [rsp+0x28], etc. Use:

r rcx rdx r8 r9      ; first four args
 dp rsp+20 L4        ; fifth and later args