AddressDescription

final class ntoseye.AddressDescription

Subclass of BaseRecord.

What an address belongs to: a loaded module (and section), a process VAD region, a kernel region, or nothing that ntoseye recognizes.

property address: int
property dtb: int

The address space of the lookup.

property kind: str

kernel-module, user-image, kernel-region, private, mapped, or unknown.

property module: AddressModule | None

The module containing the address, if any.

property region: MemoryRegion | None

The region containing the address, if any.

property section: str | None

The module section containing the address, if any.

property va_type: str | None

The _MI_SYSTEM_VA_TYPE name, for a kernel region.