Downloads:

796

Downloads of v 5.63:

25

Last Update:

17 Feb 2021

Package Maintainer(s):

Software Author(s):

  • Mark Russinovich and Ken Johnson

Tags:

kernel debug kd windbg tools sysinternals

LiveKd - Windows Sysinternals

5.63 | Updated: 17 Feb 2021

Downloads:

796

Downloads of v 5.63:

25

Maintainer(s):

Software Author(s):

  • Mark Russinovich and Ken Johnson

LiveKd - Windows Sysinternals 5.63

All Checks are Passing

2 Passing Test


Validation Testing Passed


Verification Testing Passed

Details

To install LiveKd - Windows Sysinternals, run the following command from the command line or from PowerShell:

>

To upgrade LiveKd - Windows Sysinternals, run the following command from the command line or from PowerShell:

>

To uninstall LiveKd - Windows Sysinternals, run the following command from the command line or from PowerShell:

>

NOTE: This applies to both open source and commercial editions of Chocolatey.

1. Ensure you are set for organizational deployment

Please see the organizational deployment guide

  • Open Source or Commercial:
    • Proxy Repository - Create a proxy nuget repository on Nexus, Artifactory Pro, or a proxy Chocolatey repository on ProGet. Point your upstream to https://community.chocolatey.org/api/v2. Packages cache on first access automatically. Make sure your choco clients are using your proxy repository as a source and NOT the default community repository. See source command for more information.
    • You can also just download the package and push it to a repository Download

3. Enter your internal repository url

(this should look similar to https://community.chocolatey.org/api/v2)

4. Choose your deployment method:


choco upgrade livekd -y --source="'STEP 3 URL'" [other options]

See options you can pass to upgrade.

See best practices for scripting.

Add this to a PowerShell script or use a Batch script with tools and in places where you are calling directly to Chocolatey. If you are integrating, keep in mind enhanced exit codes.

If you do use a PowerShell script, use the following to ensure bad exit codes are shown as failures:


choco upgrade livekd -y --source="'STEP 3 URL'"
$exitCode = $LASTEXITCODE

Write-Verbose "Exit code was $exitCode"
$validExitCodes = @(0, 1605, 1614, 1641, 3010)
if ($validExitCodes -contains $exitCode) {
  Exit 0
}

Exit $exitCode

- name: Ensure livekd installed
  win_chocolatey:
    name: livekd
    state: present
    version: 5.63
    source: STEP 3 URL

See docs at https://docs.ansible.com/ansible/latest/modules/win_chocolatey_module.html.


chocolatey_package 'livekd' do
  action    :install
  version  '5.63'
  source   'STEP 3 URL'
end

See docs at https://docs.chef.io/resource_chocolatey_package.html.


Chocolatey::Ensure-Package
(
    Name: livekd,
    Version: 5.63,
    Source: STEP 3 URL
);

Requires Otter Chocolatey Extension. See docs at https://inedo.com/den/otter/chocolatey.


cChocoPackageInstaller livekd
{
   Name     = 'livekd'
   Ensure   = 'Present'
   Version  = '5.63'
   Source   = 'STEP 3 URL'
}

Requires cChoco DSC Resource. See docs at https://github.com/chocolatey/cChoco.


package { 'livekd':
  provider => 'chocolatey',
  ensure   => '5.63',
  source   => 'STEP 3 URL',
}

Requires Puppet Chocolatey Provider module. See docs at https://forge.puppet.com/puppetlabs/chocolatey.


salt '*' chocolatey.install livekd version="5.63" source="STEP 3 URL"

See docs at https://docs.saltstack.com/en/latest/ref/modules/all/salt.modules.chocolatey.html.

5. If applicable - Chocolatey configuration/installation

See infrastructure management matrix for Chocolatey configuration elements and examples.

Private CDN cached downloads available for licensed customers. Never experience 404 breakages again! Learn more...

This package was approved by moderator TheCakeIsNaOH on 26 Feb 2021.

Description

Run the Kd and Windbg Microsoft kernel debuggers, which are part of the Debugging Tools for Windows package,
locally on a live system. Execute all the debugger commands that work on crash dump files to look deep inside the
system. See the Debugging Tools for Windows
documentation and the Windows Internals Book
for information on how to explore a system with the kernel debuggers.

While the latest versions of Windbg and Kd have a similar capability on Windows Vista and Server 2008, LiveKD enables
more functionality, such as viewing thread stacks with the !thread command, than Windbg and Kd's own live kernel
debugging facility.

Usage:<br>
liveKd [[-w]|[-k &lt;debugger&gt;]|[-o filename]] [-vsym] [-m[flags] [[-mp process]|[pid]]][debugger options]<br>
liveKd [[-w]|[-k &lt;debugger&gt;]|[-o filename]] -ml [debugger options]<br>
liveKd [[-w]|[-k &lt;debugger&gt;]|[-o filename]] [[-hl]|[-hv &lt;VM name&gt; [[-p]|[-hvd]]]] [debugger options]

Parameter Description
-hv Specifies the name or GUID of the Hyper-V VM to debug.
-hvd Includes hypervisor pages (Windows 8.1 and above only).
-hvl Lists the names and GUIDs of running Hyper-V VMs.
-k Specifies complete path and filename of debugger image to execute
-m Creates a mirror dump, which is a consistent view of kernel memory. Only kernel mode memory will be available, and this option may need significant amounts of available physical memory.  A flags mask that specifies which regions to include may optionally be provided (drawn from the following table, default 0x18F8):<ul style="margin-left: 20px"><br><li>0001 - process private<br><li>0002 - mapped file<br><li>0004 - shared section<br><li>0008 - page table pages<br><li>0010 - paged pool<br><li>0020 - non-paged pool<br><li>0040 - system PTEs<br><li>0080 - session pages<br><li>0100 - metadata files<br><li>0200 - AWE user pages<br><li>0400 - driver pages<br><li>0800 - kernel stacks<br><li>1000 - WS metadata<br><li>2000 - large pages</ul><br>The default captures most kernel memory contents and is recommended. This option may be used with -o to save faster, consistent dumps. Mirror dumps require Windows Vista or Windows Server 2008 or above. Sysinternals RamMap provides a graphical summary of the distribution of the available memory regions that can be selected for inclusion.
-ml Generate live dump using native support (Windows 8.1 and above only).
-mp Specifies a single process whose user mode memory contents should be included in a mirror dump. Only effective with the -m option.
-o Saves a memory.dmp to disk instead of launching the debugger.
-p Pauses the target Hyper-V VM while LiveKd is active (recommended for use with -o).
-n Specifies the name or GUID of the Hyper-V VM to debug.
-hvl Lists the names and GUIDs of running Hyper-V VMs.
-vsym Displays verbose debugging information about symbol load operations.
-w Runs windbg instead of kd.

screenshot

Notes


tools\chocolateyInstall.ps1
$ErrorActionPreference = 'Stop'

$toolsDir = (Split-Path -parent $MyInvocation.MyCommand.Definition)

$regRoot = 'HKCU:\Software\Sysinternals'
$regPkg  = 'LiveKd'

$packageArgs = @{
  packageName   = $env:ChocolateyPackageName
  unzipLocation = $toolsDir
  url           = 'https://download.sysinternals.com/files/LiveKD.zip'
  checksum      = '334823d4113f2cb41326a934721138c6b595ad6b429a00708aedea68e24773f8'
  checksumType  = 'sha256'
}

Install-ChocolateyZipPackage @packageArgs

$regPath = Join-Path $regRoot $regPkg

if (!(Test-Path $regRoot)) {
  New-Item -Path "$regRoot"
}

if (!(Test-Path $regPath)) {
  New-Item -Path "$regRoot" -Name "$regPkg"
}

Set-ItemProperty -Path "$regPath" -Name EulaAccepted -Value 1

if ((Get-ItemProperty -Path "$regPath").EulaAccepted -ne 1) {
  throw "Failure updating registry to indicate EULA acceptance"
}

Log in or click on link to see number of positives.

In cases where actual malware is found, the packages are subject to removal. Software sometimes has false positives. Moderators do not necessarily validate the safety of the underlying software, only that a package retrieves software from the official distribution point and/or validate embedded software against official distribution point (where distribution rights allow redistribution).

Chocolatey Pro provides runtime protection from possible malware.

Version Downloads Last Updated Status
LiveKd 5.4 771 Wednesday, June 8, 2016 Approved

This package has no dependencies.

Discussion for the LiveKd - Windows Sysinternals Package

Ground Rules:

  • This discussion is only about LiveKd - Windows Sysinternals and the LiveKd - Windows Sysinternals package. If you have feedback for Chocolatey, please contact the Google Group.
  • This discussion will carry over multiple versions. If you have a comment about a particular version, please note that in your comments.
  • The maintainers of this Chocolatey Package will be notified about new comments that are posted to this Disqus thread, however, it is NOT a guarantee that you will get a response. If you do not hear back from the maintainers after posting a message below, please follow up by using the link on the left side of this page or follow this link to contact maintainers. If you still hear nothing back, please follow the package triage process.
  • Tell us what you love about the package or LiveKd - Windows Sysinternals, or tell us what needs improvement.
  • Share your experiences with the package, or extra configuration or gotchas that you've found.
  • If you use a url, the comment will be flagged for moderation until you've been whitelisted. Disqus moderated comments are approved on a weekly schedule if not sooner. It could take between 1-5 days for your comment to show up.
comments powered by Disqus