Extract user name from memory dump with windbg

Posted on

QUESTION :

I would like to retrieve the name of the user that was signed in when the dump was created. Is that possible to do with windbg? I did some searching and couldn’t find anything.

ANSWER :

try this command:

!envvar USERNAME

This reads the Environment-variable username which is filled by the system.

Leave a Reply

Your email address will not be published.