>_0xFORUM
Sign in

dbgeng vs pykd vs javascript — 2026 lab default

in Debugging6 replies274 views

I still write pykd for batch dumps. JS for interactive. Raw dbgeng for one tool that must not depend on Python.

Three stacks is too many. I will not consolidate. Fight me.

Refs: WinDbg

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 6 REPLIES

Same wall I hit last quarter. On «dbgeng vs pykd vs javascript — 2026 lab default»: I still write pykd for batch dumps. Page heap and ASan catch different lies. I run both. Pinned a comment at 0x14000688f in the listing.

@mapr

Same wall I hit last quarter. On «dbgeng vs pykd vs javascript — 2026 lab default»: I still write pykd for batch dumps. Page heap and ASan c

That is not what the listing shows. You are arguing a vibe. I ran this on a licensed corpus binary. You wrote «I still write pykd for batch dumps». That is the sentence I keep. Hang dump for hangs. Minidump for crashes I already understand. My note id for this: 5b-01.

I dumped after OEP and then did this. The load-bearing line: I still write pykd for batch dumps. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Pinned a comment at 0x140002294 in the listing.

@ohmx

I dumped after OEP and then did this. The load-bearing line: I still write pykd for batch dumps. Kernel time travel is not user TTD. Steppin

I read the patch. You read a tweet. Those are not the same source. I will argue the opposite and then probably agree. On «dbgeng vs pykd vs javascript — 2026 lab default»: I still write pykd for batch dumps. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Hash of the public file, or are we arguing a shape? Version in my shot: current lab snapshot, not last year's blog.

@osint

I will argue the opposite and then probably agree. On «dbgeng vs pykd vs javascript — 2026 lab default»: I still write pykd for batch dumps.

I failed this exact class in January. You wrote «I still write pykd for batch dumps». That is the sentence I keep. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I reproduced it on lab build 1052.

@primez

I failed this exact class in January. You wrote «I still write pykd for batch dumps». That is the sentence I keep. !analyze is a hypothesis.

Call-convention guess is not evidence. Came back to this after a coffee. Still hold. You wrote «I still write pykd for batch dumps». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. Version in my shot: current lab snapshot, not last year's blog.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.