{
	"id": "4cffa8eb-79e7-4914-aa2e-7c94916e48a9",
	"created_at": "2026-04-06T01:29:20.076663Z",
	"updated_at": "2026-04-10T03:20:05.590494Z",
	"deleted_at": null,
	"sha1_hash": "cb8e3053a19abdd7680c65d84557ef1873cd8a8d",
	"title": "GFlags Overview - Windows drivers",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 41724,
	"plain_text": "GFlags Overview - Windows drivers\r\nBy Bradben\r\nArchived: 2026-04-06 00:15:20 UTC\r\nGFlags (gflags.exe), the Global Flags Editor, enables and disables advanced internal system diagnostic and\r\ntroubleshooting features. You can run GFlags from a Command Prompt window or use its graphical user interface\r\ndialog box.\r\nFor information on how to install and locate gflags.exe, see GFlags.\r\nUse GFlags to activate the following features:\r\nRegistry\r\nSet system-wide debugging features for all processes running on the computer. These settings are stored in the\r\nGlobalFlag registry entry (HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session\r\nManager\\GlobalFlag). They take effect when you restart Windows and remain effective until you change them\r\nand restart again.\r\nKernel flag settings\r\nSet debugging features for this session. These settings are effective immediately, but are lost when Windows shuts\r\ndown. The settings affect all processes started after this command completes.\r\nImage file settings\r\nSet debugging features for a particular program. These settings are stored in a GlobalFlag registry entry for each\r\nprogram (HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File\r\nExecution Options\\ImageFileName\\GlobalFlag). They take effect when you restart the program and remain\r\neffective until you change them.\r\nDebugger\r\nSpecify that a particular program always runs in a debugger. This setting is stored in the registry. It is effective\r\nimmediately and remains effective until you change it. (This feature is available only in the Global Flags dialog\r\nbox.)\r\nLaunch\r\nRun a program with the specified debugging settings. The debugging settings are effective until the program stops.\r\n(This feature is available only from the Global Flags dialog box.)\r\nSpecial Pool\r\nRequest that allocation with a specified pool tag or of a specified size are filled from the special pool. This feature\r\nhelps you to detect and identify the source of errors in kernel pool use, such as writing beyond the allocated\r\nmemory space, or referring to memory that has already been freed.\r\nhttps://docs.microsoft.com/windows-hardware/drivers/debugger/gflags-overview\r\nPage 1 of 2\n\nBeginning in Windows Vista, you can enable, disable, and configure the special pool feature (Kernel Special Pool\r\nTag) as a kernel flags setting, which does not require a reboot, or as a registry setting, which requires a reboot.\r\nPage heap verification\r\nEnable, disable, and configure page heap verification for a program. When enabled, page heap monitors dynamic\r\nheap memory operations, including allocation and free operations, and causes a debugger break when it detects a\r\nheap error.\r\nSilent process exit\r\nEnable, disable, and configure monitoring and reporting of silent exits for a process. You can specify actions that\r\noccur when a process exits silently, including notification, event logging, and creation of dump files. For more\r\ninformation, see Monitoring Silent Process Exit.\r\nSource: https://docs.microsoft.com/windows-hardware/drivers/debugger/gflags-overview\r\nhttps://docs.microsoft.com/windows-hardware/drivers/debugger/gflags-overview\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"MITRE"
	],
	"references": [
		"https://docs.microsoft.com/windows-hardware/drivers/debugger/gflags-overview"
	],
	"report_names": [
		"gflags-overview"
	],
	"threat_actors": [],
	"ts_created_at": 1775438960,
	"ts_updated_at": 1775791205,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/cb8e3053a19abdd7680c65d84557ef1873cd8a8d.pdf",
		"text": "https://archive.orkl.eu/cb8e3053a19abdd7680c65d84557ef1873cd8a8d.txt",
		"img": "https://archive.orkl.eu/cb8e3053a19abdd7680c65d84557ef1873cd8a8d.jpg"
	}
}