Sign in

Debugger

@debugger.bsky.social
231 followers 34 following 17 posts

I’m a problem solver with a passion for hardcore troubleshooting. If you think it can’t be fixed, that’s exactly when I get interested.

PostsRepliesMedia
Reposted by Debugger
Evan McBroom @evanmcbroom.bsky.social · 16/10/2025
@reconmtl.bsky.social has uploaded the majority of the 2025 talks, including my talk on LSA. You can check it out at the below link if you'd like. Thank you again to the organizers and everyone else who helps put on the conference. I look forward to coming back! youtu.be/G2CfMWXLU1U?...
youtu.be
Recon 2025 - The Finer Details of LSA Credential Recovery
YouTube video by Recon Conference
0115
Debugger @debugger.bsky.social · 16/10/2025
Just posted a write-up on a DC hang traced to a deadlock inside LSASS. I break down call stacks, the blocked threads, and how doing LDAP work in DllMain triggered the issue. medium.com/@Debugger/se...
medium.com
Server hang explained: LSASS deadlock between mswsock and LoaderLock
TLDR: For weeks a customer saw random domain controllers freeze with no clear errors in Event Viewer. It looked like network timeouts and…
000
Reposted by Debugger
Patrick Matula @patrickmatula.com · 10/10/2025
Interesting memory dump analysis in WinDbg. I think it's very useful not to show only the "golden path" to the solution!
001
Debugger @debugger.bsky.social · 08/10/2025
To be honest, I can't believe I missed this. The !analyze -v command was already pointing to the driver as the cause, but I ignored it. I guess I'll have to double-check more carefully next time, but I'm satisfied with the analysis I've done. 😅
000
Debugger @debugger.bsky.social · 21/09/2025
Of course the private symbols are not available, so the ETW traces might be difficult to read. Other than that, it collects relevant data though :-)
000
Debugger @debugger.bsky.social · 21/09/2025
Anyone used the TSS Troubleshooting script from MSFT before? I saw an Escalation Engineer used it, so I'd thought it could be interesting to others as well. The use-case was troubleshooting LSASS high CPU on a DC... learn.microsoft.com/en-us/troubl...
210
Debugger @debugger.bsky.social · 13/09/2025
Has anyone already ditched Twitter for Bluesky? I’m still more active on Twitter, but I’ve noticed some people have moved over to Bluesky.
440
Debugger @debugger.bsky.social · 12/09/2025
Eww PowerShell.
000
Debugger @debugger.bsky.social · 12/09/2025
New blog post of me analyzing a crash dump with the bugcheck 0x9F. Root cause was a power IRP timeout in RAS SSTP during a device removal. The post walks PnP locks, the stuck IRP, and more, including my thought process. Check it out here: medium.com/@Debugger/po...
medium.com
Power IRP timeout in RAS SSTP causes Blue Screen 0x9F during sleep
We’ll first start with the !winde.infocommand, which tells us that this system is a Windows 10 version 19041 on an 8 core Intel machine…
031
Debugger @debugger.bsky.social · 11/05/2025
Ever tried VSS tracing? I’ve been using it to troubleshoot Volume Shadow Copy issues. It’s super useful but not widely known, so I wrote a quick blog post about it. medium.com/@Debugger/tr...
medium.com
Troubleshooting Windows Volume Shadow Copy Service
When troubleshooting problems with Volume Shadow Copy Service (VSS) on Windows, event logs and error codes don’t always tell the full…
000
Debugger @debugger.bsky.social · 07/04/2025
Agreed. I still use Twitter though, but I've reduced my social media time a lot.
020
Debugger @debugger.bsky.social · 07/04/2025
Yeah, same here :)
000
Debugger @debugger.bsky.social · 07/04/2025
Is there anyone who completely ditched Twitter and now only uses Blue Sky? 😅
310
Debugger @debugger.bsky.social · 05/02/2025
Always wanted to know how to use Time Travel Debugging (TTD) to record lsass.exe? Well, here you have a chance to go for it. I haven't seen much documentation online where this is discussed. github.com/DebugPrivile...
github.com
InsightEngineering/Time Travel Debugging (TTD)/2. TTD FAQ and Troubleshooting at main · DebugPrivilege/InsightEngineering
Hardcore Debugging. Contribute to DebugPrivilege/InsightEngineering development by creating an account on GitHub.
010
Debugger @debugger.bsky.social · 15/01/2025
For those that are doing a lot of log analysis. textanalysistool.github.io is a free open-source tool that I've been using to analyze ESXi, Citrix, MpLogs, Teams support logs, etc. It can be useful when you deal with those raw format logs.
textanalysistool.github.io
TextAnalysisTool.NET
TextAnalysisTool.NET: A program designed to excel at viewing, searching, and navigating large files quickly and efficiently.
000
Debugger @debugger.bsky.social · 09/01/2025
Who uses WinDbg as well in their daily work?
000
Debugger @debugger.bsky.social · 07/01/2025
- No more pizza with pineapple
010
Debugger @debugger.bsky.social · 03/01/2025
Interesting old blog post from MSRC where they are talking about their in-house tool called ''VulnScan'' to automate the triage and root cause analysis of memory corruption issues. It's built on top of WinDbg and Time Travel Debugging as well! msrc.microsoft.com/blog/2017/10...
msrc.microsoft.com
VulnScan – Automated Triage and Root Cause Analysis of Memory Corruption Issues  | MSRC Blog | Microsoft Security Response Center California Consumer Privacy Ac...
The Microsoft Security Response Center (MSRC) receives reports about potential vulnerabilities in our products and it’s the job of our engineering team to assess the severity, impact, and root cause o...
020
Debugger @debugger.bsky.social · 31/12/2024
Wishing everyone a Happy and Healthy 2025! 🎉- In case you missed it, I created a GitHub repository in 2024 covering Windows Debugging topics. It includes using tools like WinDbg to analyze memory dumps and more. If you're into Windows, check it out here: github.com/DebugPrivile...
github.com
GitHub - DebugPrivilege/InsightEngineering: Hardcore Debugging
Hardcore Debugging. Contribute to DebugPrivilege/InsightEngineering development by creating an account on GitHub.
071