Open zhouat opened 6 years ago
C:\Program Files\Windows Kits\10\Debuggers\x86>gflags.exe -I WINWORD.EXE -ust -hpa gflags.exe -I WINWORD.EXE -ust -hpa +ust +hpa
!heap -p -a 05e10ff0
pykd https://labs.mwrinfosecurity.com/blog/heap-tracing-with-windbg-and-python/