This commit is contained in:
Elliot Killick
2025-02-13 21:26:23 -05:00
parent caee7304d8
commit c357c3633f
4 changed files with 2115 additions and 2042 deletions
+831 -758
View File
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -71,7 +71,7 @@ This analyis command's only action right now is to print the assembly instructio
### Check Common Lock States
Check the state of common locks including the load owner or load lock, loader lock, the PEB lock, and the heap lock:
Check the state of common locks including the load lock, loader lock, the PEB lock, and the heap lock:
```
!handle poi(ntdll!LdrpLoadCompleteEvent) 8
+1 -1
View File
@@ -19,7 +19,7 @@ Windows UCRT: Critical section lock covering CRT exit (`ucrtbase!common_exit` fu
- [Source code](https://github.com/huangqinjin/ucrt/blob/master/startup/exit.cpp#L195) (the UCRT is source available)
Windows MSVCRT: Critical section lock covering CRT exit (`msvcrt!doexit` function), EXE `atexit` (registration and routine execution), and DLL `atexit` (registration and routine execution): `msvcrt!CrtLock_Exit`
- MSVCRT is an anicent CRT, but it is the one applications and DLLs link with when Microsoft compiles Windows (for backward compatibility reasons)
- MSVCRT is an ancient C runtime, but it is the one Windows internally links to for applications and libraries that Microsoft includes with the operating system (for backward compatibility reasons), with possibly a few minor exceptions
## Loader Lock
File diff suppressed because it is too large Load Diff