BlahCats Blog

Tales of a binary encoded life...

Install Hyper-V & Sandbox on Windows 10/11 Home

Published by hugsy , on 6 August 2022 , under minis

Another lie, probably put in place from MS marketing team to force the hand and make more people purchase Windows 10/11 Professional licenses: Hyper-V and Windows Sandbox can be installed on Windows 1…

WinDbgX undocumented workspace options

Published by hugsy , on 17 July 2022 , under minis

How to use WinDbgX workspaces to make debugging even easier. Workspaces WinDbgX workspaces (suffixed .debugTargets) are nothing more than XML files that instructs WinDbgX how to process with the curre…

Setup KDCOM for 2 Hyper-V VMs

Published by hugsy , on 14 July 2022 , under minis

How to use Hyper-V to debug using KdCOM from 2 VMs, one debugging the other. Debuggee Follow the setup here to setup a BCD profile for KdCom in the VM. Shutdown the VM and in a privileged prompt on th…

Enumerating processes from KD

Published by hugsy , on 23 May 2020 , under minis

This is tiny Post-It post to remind of different ways to enumerate processes from KD: using nt!PsActiveProcessHead dx Debugger.Utility.Collections.FromListEntry( *(nt!_LIST_ENTRY*)&(nt!PsActiveP…

Quick visualization of a binary file

Published by hugsy , on 2 December 2018 , under minis

Here’s a simple trick that I learned from the amazing @scanlime to quickly (and universally) visualize the distribution of byte of any binary file, using the Portable Graymap Format (PGM) format. …