1. Get Address dt _PEB @$peb ProcessParameters 2. Dump Address dt ntdll!_RTL_USER_PROCESS_PARAMETERS <Address>