Inspect captured data
Start with the call
Section titled “Start with the call”Select a row in Syscall Trace. Read the call name, argument direction and return value together. An input buffer can represent what the program supplied; an output buffer can represent what the kernel returned.
Flags and options are decoded where supported, including file options, socket options and process controls. Unknown bits are retained. Right-click numeric values to copy common representations.
Open the captured bytes
Section titled “Open the captured bytes”Open a captured object in its data window. The available representations include:
- UTF-8 and ASCII text.
- Hex and hexdump.
- C arrays, Base64 and escaped forms.
Choose the representation appropriate for the data. A binary buffer can contain zero bytes; text decoding alone does not establish its full contents.
Data windows use paged reads for retained captures instead of limiting inspection to the initial preview. Copy the chosen representation for notes or another tool.
Read incomplete observations
Section titled “Read incomplete observations”Keep gap, error, truncation and missing-range states with the value. An unreadable range is not an empty buffer. A partial string is not necessarily the full path or argument.
The program can change memory while it is being observed. Kernel-side capture uses bounded, non-faulting observation; it does not make the program’s memory an atomic snapshot.
If calls or object data are missing, inspect the transport and storage loss counters before drawing conclusions.