Where can I get the current label counter in a 64-bit dump of Windows?

There is one KeTickCount character that works in 32-bit mode, but when I applied it in my 64-bit dump (Windows 2008), it no longer works. Have the window value changed?

The only approach I can take is to use ".time" to get the current uptime and multiply it by ticksPerSecond, which is difficult and inaccurate.

+5
source share
2 answers

Launch it! kuser to get it in windbg.

+2
source

According to several messages on the Internet, it has a hard-coded address 0FFFFF78000000320h. I have not tried, though.

0

All Articles