You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windbg脚本需求:查找涉及指定驱动的线程调用栈

Windbg内核转储分析脚本:查找调用栈包含指定驱动的线程

下面是一个可直接在Windbg中运行的JScript脚本,用于遍历内核转储中的所有线程,检查其调用栈是否包含指定驱动模块:

// 指定要查找的驱动模块名(区分大小写,按需修改)
var targetModule = "mydriver.sys";

// 获取系统进程列表并提取PID
var processes = host.namespace.Debugger.Utility.Control.ExecuteCommand("!process 0 0");
var processIdList = [];

for (var line of processes) {
    var pidMatch = line.match(/PROCESS\s+([0-9a-fA-F]+)\s+/);
    if (pidMatch && pidMatch[1]) {
        processIdList.push(pidMatch[1]);
    }
}

// 遍历每个进程,检查下属线程
print("=== 开始查找调用栈包含 " + targetModule + " 的线程 ===");
for (var pid of processIdList) {
    var threads = host.namespace.Debugger.Utility.Control.ExecuteCommand("!process " + pid + " 7");
    var currentThreadId = "";
    var currentProcessName = "";
    
    for (var line of threads) {
        // 提取进程名
        var procNameMatch = line.match(/Image:\s+(\S+)/);
        if (procNameMatch) {
            currentProcessName = procNameMatch[1];
        }
        
        // 提取线程ID
        var threadMatch = line.match(/THREAD\s+([0-9a-fA-F]+)\s+/);
        if (threadMatch) {
            currentThreadId = threadMatch[1];
        }
        
        // 检查当前行是否包含目标驱动模块
        if (line.includes(targetModule)) {
            print("--------------------------------------------------");
            print("进程名: " + currentProcessName);
            print("进程PID: " + pid);
            print("线程TID: " + currentThreadId);
            print("调用栈包含目标模块: " + targetModule);
            // 可选:打印当前线程完整调用栈
            print("完整调用栈:");
            var stack = host.namespace.Debugger.Utility.Control.ExecuteCommand("k " + currentThreadId);
            for (var stackLine of stack) {
                print(stackLine);
            }
        }
    }
}
print("=== 查找完成 ===");

使用步骤

  1. 打开Windbg并加载目标内核转储文件
  2. 执行命令 .load jsprovider 确保加载JScript支持(未加载时需要执行)
  3. 将脚本保存为 FindThreadsWithDriver.js
  4. 在Windbg中执行命令 !js "FindThreadsWithDriver.js" 启动脚本

注意事项

  • 请将脚本中的targetModule替换为实际要查找的驱动模块名,注意区分大小写
  • 大体积转储文件遍历线程耗时较长,请耐心等待
  • 脚本会输出包含目标模块的线程所属进程信息及完整调用栈,便于后续分析
  • 可根据需求修改脚本中的打印逻辑或匹配规则,调整输出内容

内容的提问来源于stack exchange,提问作者ymike

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 20:12:35