DebugPrivilege
@debugger.bsky.social
š¤ 221
š„ 34
š 18
reposted by
DebugPrivilege
Evan McBroom
about 2 months ago
@reconmtl.bsky.social
has uploaded the majority of the 2025 talks, including my talk on LSA. You can check it out at the below link if you'd like. Thank you again to the organizers and everyone else who helps put on the conference. I look forward to coming back!
youtu.be/G2CfMWXLU1U?...
loading . . .
Recon 2025 - The Finer Details of LSA Credential Recovery
YouTube video by Recon Conference
https://youtu.be/G2CfMWXLU1U?si=8QKZf3LYeYFt88Sx
0
9
5
Just posted a write-up on a DC hang traced to a deadlock inside LSASS. I break down call stacks, the blocked threads, and how doing LDAP work in DllMain triggered the issue.
medium.com/@Debugger/se...
loading . . .
Server hang explained: LSASS deadlock between mswsock and LoaderLock
TLDR: For weeks a customer saw random domain controllers freeze with no clear errors in Event Viewer. It looked like network timeouts andā¦
https://medium.com/@Debugger/server-hang-explained-lsass-deadlock-between-mswsock-and-loaderlock-934ac75586ee
about 2 months ago
0
0
0
reposted by
DebugPrivilege
Patrick Matula
about 2 months ago
Interesting memory dump analysis in WinDbg. I think it's very useful not to show only the "golden path" to the solution!
add a skeleton here at some point
0
0
1
New blog post: Bugcheck 0x154 that was related to Intel RST driver causing storage I/O failures. I walk through different debugging techniques I used to prove it, from following IRPs and MiWaitForInPageComplete to more shenanigans.
medium.com/@Debugger/un...
loading . . .
UNEXPECTED_STORE_EXCEPTION (0x154)āāāRoot Cause: Storage I/O Failure in iaStorAC.sys
TLDR: I initially thought the crash occurred during hibernation because the Intel graphics driver failed to power down the GPU. Thisā¦
https://medium.com/@Debugger/unexpected-store-exception-0x154-root-cause-storage-i-o-failure-in-iastorac-sys-2745d9de6202
2 months ago
0
2
0
Anyone used the TSS Troubleshooting script from MSFT before? I saw an Escalation Engineer used it, so I'd thought it could be interesting to others as well. The use-case was troubleshooting LSASS high CPU on a DC...
learn.microsoft.com/en-us/troubl...
3 months ago
2
1
0
Has anyone already ditched Twitter for Bluesky? Iām still more active on Twitter, but Iāve noticed some people have moved over to Bluesky.
3 months ago
4
4
1
New blog post of me analyzing a crash dump with the bugcheck 0x9F. Root cause was a power IRP timeout in RAS SSTP during a device removal. The post walks PnP locks, the stuck IRP, and more, including my thought process. Check it out here:
medium.com/@Debugger/po...
loading . . .
Power IRP timeout in RAS SSTP causes Blue Screen 0x9F during sleep
Weāll first start with theĀ !winde.infocommand, which tells us that this system is a Windows 10 version 19041 on an 8 core Intel machineā¦
https://medium.com/@Debugger/power-irp-timeout-in-ras-sstp-causes-blue-screen-0x9f-during-sleep-e59cb76f291c
3 months ago
0
3
2
Ever tried VSS tracing? Iāve been using it to troubleshoot Volume Shadow Copy issues. Itās super useful but not widely known, so I wrote a quick blog post about it.
medium.com/@Debugger/tr...
loading . . .
Troubleshooting Windows Volume Shadow Copy Service
When troubleshooting problems with Volume Shadow Copy Service (VSS) on Windows, event logs and error codes donāt always tell the fullā¦
https://medium.com/@Debugger/troubleshooting-windows-volume-shadow-copy-service-7849a4abfe87
7 months ago
0
0
0
Is there anyone who completely ditched Twitter and now only uses Blue Sky? š
8 months ago
3
1
0
Always wanted to know how to use Time Travel Debugging (TTD) to record lsass.exe? Well, here you have a chance to go for it. I haven't seen much documentation online where this is discussed.
github.com/DebugPrivile...
loading . . .
InsightEngineering/Time Travel Debugging (TTD)/2. TTD FAQ and Troubleshooting at main Ā· DebugPrivilege/InsightEngineering
Hardcore Debugging. Contribute to DebugPrivilege/InsightEngineering development by creating an account on GitHub.
https://github.com/DebugPrivilege/InsightEngineering/tree/main/Time%20Travel%20Debugging%20(TTD)/2.%20TTD%20FAQ%20and%20Troubleshooting
10 months ago
0
1
0
For those that are doing a lot of log analysis.
textanalysistool.github.io
is a free open-source tool that I've been using to analyze ESXi, Citrix, MpLogs, Teams support logs, etc. It can be useful when you deal with those raw format logs.
loading . . .
TextAnalysisTool.NET
TextAnalysisTool.NET: A program designed to excel at viewing, searching, and navigating large files quickly and efficiently.
https://textanalysistool.github.io/
11 months ago
0
0
0
Who uses WinDbg as well in their daily work?
11 months ago
0
0
0
Interesting old blog post from MSRC where they are talking about their in-house tool called ''VulnScan'' to automate the triage and root cause analysis of memory corruption issues. It's built on top of WinDbg and Time Travel Debugging as well!
msrc.microsoft.com/blog/2017/10...
loading . . .
VulnScan ā Automated Triage and Root Cause Analysis of Memory Corruption IssuesĀ | MSRC Blog | Microsoft Security Response Center California Consumer Privacy Ac...
The Microsoft Security Response Center (MSRC) receives reports about potential vulnerabilities in our products and itās the job of our engineering team to assess the severity, impact, and root cause o...
https://msrc.microsoft.com/blog/2017/10/vulnscan-automated-triage-and-root-cause-analysis-of-memory-corruption-issues/
11 months ago
0
2
0
Wishing everyone a Happy and Healthy 2025! š- In case you missed it, I created a GitHub repository in 2024 covering Windows Debugging topics. It includes using tools like WinDbg to analyze memory dumps and more. If you're into Windows, check it out here:
github.com/DebugPrivile...
loading . . .
GitHub - DebugPrivilege/InsightEngineering: Hardcore Debugging
Hardcore Debugging. Contribute to DebugPrivilege/InsightEngineering development by creating an account on GitHub.
https://github.com/DebugPrivilege/InsightEngineering
11 months ago
0
7
1
you reached the end!!
feeds!
log in