githubEdit

Extension Commands

!a (assemble physical address)chevron-right!pte (display page-level address and entries)chevron-right!db, !dc, !dd, !dq (read physical memory)chevron-right!eb, !ed, !eq (edit physical memory)chevron-right!sb, !sd, !sq (search physical memory)chevron-right!u, !u64, !u2, !u32 (disassemble physical address)chevron-right!dt (display and map physical memory to structures)chevron-right!track (track and map function calls and returns to the symbols)chevron-right!epthook (hidden hook with EPT - stealth breakpoints)chevron-right!epthook2 (hidden hook with EPT - detours)chevron-right!monitor (monitor read/write/execute to a range of memory)chevron-right!syscall, !syscall2 (hook system-calls)chevron-right!sysret, !sysret2 (hook SYSRET instruction execution)chevron-right!mode (detect kernel-to-user and user-to-kernel transitions)chevron-right!cpuid (hook CPUID instruction execution)chevron-right!msrread (hook RDMSR instruction execution)chevron-right!msrwrite (hook WRMSR instruction execution)chevron-right!tsc (hook RDTSC/RDTSCP instruction execution)chevron-right!pmc (hook RDPMC instruction execution)chevron-right!vmcall (hook hypercalls)chevron-right!exception (hook first 32 entries of IDT)chevron-right!interrupt (hook external device interrupts)chevron-right!dr (hook access to debug registers)chevron-right!ioin (hook IN instruction execution)chevron-right!ioout (hook OUT instruction execution)chevron-right!xsetbv (hook XSETBV instruction execution)chevron-right!hide (enable transparent-mode)chevron-right!unhide (disable transparent-mode)chevron-right!measure (measuring and providing details for transparent-mode)chevron-right!va2pa (convert a virtual address to physical address)chevron-right!pa2va (convert physical address to virtual address)chevron-right!dump (save the physical memory into a file)chevron-right!pcitree (show PCI/PCIe device tree)chevron-right!pcicam (dump the PCI/PCIe configuration space)chevron-right!idt (show Interrupt Descriptor Table entries)chevron-right!smi (trigger and show System Management Interrupt functionalities)chevron-right!apic (dump local APIC entries in XAPIC and X2APIC modes)chevron-right!ioapic (dump I/O APIC)chevron-right

Last updated