<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Who opened that file?</title>
	<link>https://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/</link>
	<description>Structural and Behavioral Patterns for Software Diagnostics, Forensics and Prognostics</description>
	<pubDate>Wed, 06 May 2026 03:26:17 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Software Generalist &#187; Blog Archive &#187; Reading Notebook: 18-August-09</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/#comment-89454</link>
		<dc:creator>Software Generalist &#187; Blog Archive &#187; Reading Notebook: 18-August-09</dc:creator>
		<pubDate>Tue, 18 Aug 2009 14:09:36 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/#comment-89454</guid>
		<description>[...] !devhandles WinDbg command, searching for open files (p. 155) - it looks like it is done through device prefix to a file name; I&#8217;ve done simple text search for a file name if known through all handle tables: http://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/ [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] !devhandles WinDbg command, searching for open files (p. 155) - it looks like it is done through device prefix to a file name; I&#8217;ve done simple text search for a file name if known through all handle tables: <a href="http://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/" rel="nofollow">http://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/</a> [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dmitry Vostokov</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/#comment-89452</link>
		<dc:creator>Dmitry Vostokov</dc:creator>
		<pubDate>Tue, 18 Aug 2009 14:04:18 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/#comment-89452</guid>
		<description>I found another technique via !devhandles WinDbg command, searching for open files (Windows Internals, 5th edition, p. 155)</description>
		<content:encoded><![CDATA[<p>I found another technique via !devhandles WinDbg command, searching for open files (Windows Internals, 5th edition, p. 155)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kobi Ben Tzvi</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/#comment-34175</link>
		<dc:creator>Kobi Ben Tzvi</dc:creator>
		<pubDate>Mon, 14 Jul 2008 12:03:33 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2008/05/30/who-opened-that-file/#comment-34175</guid>
		<description>I usually use ProcExp's find handle command, but this seems to be great addition to the toolbox. 

Thanks Dima</description>
		<content:encoded><![CDATA[<p>I usually use ProcExp&#8217;s find handle command, but this seems to be great addition to the toolbox. </p>
<p>Thanks Dima</p>
]]></content:encoded>
	</item>
</channel>
</rss>
