WinDbg Stack Inspection Commands
Use these commands to inspect values that have been pushed onto the stack, especially right before a function call.
Core command
dd esp L2
| Part | Meaning |
|---|---|
dd |
dump dwords — display 32-bit values |
esp |
start at the address held by ESP (top of stack) |
L2 |
show 2 dwords |
On x86, push writes a 4-byte value to [esp] and decrements ESP by 4. So immediately after a push, dd esp L1 shows the value that was just pushed.
Common variants
| Command | Purpose |
|---|---|
dd esp L4 |
dump 4 dwords from top of stack |
da esp |
dump ASCII string at top of stack |
du esp |
dump Unicode string at top of stack |
dp esp L3 |
pointer-sized dump (works on x86 and x64) |
dps esp L10 |
dump pointers with symbol resolution |
dpp esp L5 |
dump pointer contents (dereferences each pointer) |
64-bit note
On x64 the first four integer/pointer arguments are passed in registers (RCX, RDX, R8, R9), not on the stack. Additional arguments are at [rsp+0x20], [rsp+0x28], etc. Use:
r rcx rdx r8 r9 ; first four args
dp rsp+20 L4 ; fifth and later args