Windbg脚本需求:查找涉及指定驱动的线程调用栈
Windbg内核转储分析脚本:查找调用栈包含指定驱动的线程
下面是一个可直接在Windbg中运行的JScript脚本,用于遍历内核转储中的所有线程,检查其调用栈是否包含指定驱动模块:
// 指定要查找的驱动模块名(区分大小写,按需修改) var targetModule = "mydriver.sys"; // 获取系统进程列表并提取PID var processes = host.namespace.Debugger.Utility.Control.ExecuteCommand("!process 0 0"); var processIdList = []; for (var line of processes) { var pidMatch = line.match(/PROCESS\s+([0-9a-fA-F]+)\s+/); if (pidMatch && pidMatch[1]) { processIdList.push(pidMatch[1]); } } // 遍历每个进程,检查下属线程 print("=== 开始查找调用栈包含 " + targetModule + " 的线程 ==="); for (var pid of processIdList) { var threads = host.namespace.Debugger.Utility.Control.ExecuteCommand("!process " + pid + " 7"); var currentThreadId = ""; var currentProcessName = ""; for (var line of threads) { // 提取进程名 var procNameMatch = line.match(/Image:\s+(\S+)/); if (procNameMatch) { currentProcessName = procNameMatch[1]; } // 提取线程ID var threadMatch = line.match(/THREAD\s+([0-9a-fA-F]+)\s+/); if (threadMatch) { currentThreadId = threadMatch[1]; } // 检查当前行是否包含目标驱动模块 if (line.includes(targetModule)) { print("--------------------------------------------------"); print("进程名: " + currentProcessName); print("进程PID: " + pid); print("线程TID: " + currentThreadId); print("调用栈包含目标模块: " + targetModule); // 可选:打印当前线程完整调用栈 print("完整调用栈:"); var stack = host.namespace.Debugger.Utility.Control.ExecuteCommand("k " + currentThreadId); for (var stackLine of stack) { print(stackLine); } } } } print("=== 查找完成 ===");
使用步骤
- 打开Windbg并加载目标内核转储文件
- 执行命令
.load jsprovider确保加载JScript支持(未加载时需要执行) - 将脚本保存为
FindThreadsWithDriver.js - 在Windbg中执行命令
!js "FindThreadsWithDriver.js"启动脚本
注意事项
- 请将脚本中的
targetModule替换为实际要查找的驱动模块名,注意区分大小写 - 大体积转储文件遍历线程耗时较长,请耐心等待
- 脚本会输出包含目标模块的线程所属进程信息及完整调用栈,便于后续分析
- 可根据需求修改脚本中的打印逻辑或匹配规则,调整输出内容
内容的提问来源于stack exchange,提问作者ymike
相关产品推荐
相关产品推荐

