Driver load/unload fails if WinDbg attached with breakpoint

匆匆过客 提交于 2019-12-05 18:31:38

The command you are looking for is sxe ld:MyDriver1

This will break when the driver is mapped into memory but before calling MyDriver1!DriverEntry and will allow you to put breakpoints at DriverEntry.

The command bu MyDriver1 puts a breakpoint in the first byte of the PE header of the driver image.

Also, clean up breakpoints after you unload the driver otherwise you cause the debugger to modify memory that could be allocated for something else.

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!