1 bookmark for 2025-03-04

93.

Recognizing patterns in memory

www.timdbg.com/posts/recognizing-patterns

Just run !address <address>, which will tell you if the address is valid in the current process. The odds of a 64-bit value being a pointer by chance is quite low.

p.s. речь про WinDbg, но метод всё забавный, автоматизировать бы