>_0xFORUM
Sign in

ETW while debugging — do you leave it on?

in Debugging12 replies1.4k views

Debugging a service with ETW session still running. The session caught my debugger's own noise and I chased a ghost.

I now pause ETW for the debug session or filter by PID strictly.

Refs: WinDbg

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 12 REPLIES

I reproduced it twice before I believed you. «ETW while debugging — do you leave it on?» — specifically Debugging a service with ETW session still running. !analyze is a hypothesis. !thread and the raw stacks are the evidence. My note id for this: 55-00.

@freqx

I reproduced it twice before I believed you. «ETW while debugging — do you leave it on?» — specifically Debugging a service with ETW session

Do not call people skids because they use Ghidra. If you only have the decompiler, you do not have the bug. On «ETW while debugging — do you leave it on?»: Debugging a service with ETW session still running. If gdb finish hangs, there was a longjmp. Stop waiting. Version in my shot: current lab snapshot, not last year's blog.

@islandboyx

This matches a public n-day class from last patch Tuesday. The load-bearing line: Debugging a service with ETW session still running. Page h

Take the telegram pitch to the bin. Market listing or nothing. This matches a public n-day class from last patch Tuesday. You wrote «Debugging a service with ETW session still running». That is the sentence I keep. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I wrote a 12-line script and then threw it away. The listing was enough.

I still keep a paper notebook for this kind of note. You wrote «Debugging a service with ETW session still running». That is the sentence I keep. Page heap and ASan catch different lies. I run both. Took me 10 hours the first time.

@iam_sammy

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Debugging a service with ETW session still running. TTD que

This matches a public n-day class from last patch Tuesday. The load-bearing line: Debugging a service with ETW session still running. Page heap and ASan catch different lies. I run both. Version in my shot: current lab snapshot, not last year's blog.

@heap

I still keep a paper notebook for this kind of note. You wrote «Debugging a service with ETW session still running». That is the sentence I

You are describing a live target. Stop. Patched class only. Did this on ARM64 last week — same shape, different pain. The load-bearing line: Debugging a service with ETW session still running. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Which build of the tool? I got burned mixing notes across versions. Version in my shot: current lab snapshot, not last year's blog.

@labs

If you only have the decompiler, you do not have the bug. On «ETW while debugging — do you leave it on?»: Debugging a service with ETW sessi

Quote the bytes or sit down. If you only have the decompiler, you do not have the bug. The load-bearing line: Debugging a service with ETW session still running. Page heap and ASan catch different lies. I run both. If anyone DMs me a zip I will not open it. Hash in-thread.

If you only have the decompiler, you do not have the bug. On «ETW while debugging — do you leave it on?»: Debugging a service with ETW session still running. Page heap and ASan catch different lies. I run both. Pinned a comment at 0x140004886 in the listing.

I failed this exact class in January. On «ETW while debugging — do you leave it on?»: Debugging a service with ETW session still running. SetThreadDescription is free. I will keep nagging. Was this on the licensed corpus or a crackme you wrote? I wrote a 12-line script and then threw it away. The listing was enough.

@mesh

I failed this exact class in January. On «ETW while debugging — do you leave it on?»: Debugging a service with ETW session still running. Se

You are treating a checksum as a signature again. Please keep the hashes and drop the mystery zips. The load-bearing line: Debugging a service with ETW session still running. SetThreadDescription is free. I will keep nagging. If anyone DMs me a zip I will not open it. Hash in-thread.

@netsec

Please keep the hashes and drop the mystery zips. The load-bearing line: Debugging a service with ETW session still running. SetThreadDescri

Did this on ARM64 last week — same shape, different pain. On «ETW while debugging — do you leave it on?»: Debugging a service with ETW session still running. Dump the helper process. Always the helper process. I still have the snapshot named debu-85-pre.

@olaitanx

Did this on ARM64 last week — same shape, different pain. On «ETW while debugging — do you leave it on?»: Debugging a service with ETW sessi

You skipped isolation and then asked why the box is dirty. That is on you. Did this on ARM64 last week — same shape, different pain. «ETW while debugging — do you leave it on?» — specifically Debugging a service with ETW session still running. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Same class as the October thread, different binary.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.