AlpcMessage

final class ntoseye.AlpcMessage

Subclass of BaseRecord.

A _KALPC_MESSAGE (!alpc /m). A field is None if this Windows build does not have it, or if ntoseye cannot read it.

property address: int
property attributes: Record

The _KALPC_MESSAGE_ATTRIBUTES fields in this build, by snake_case name.

property callback_id: int | None
property cancel_sequence_no: int | None
property client_process_id: int | None

PortMessage.ClientId, the sender.

property client_thread_id: int | None
property data_length: int | None
property extension_buffer_size: int | None
property message_id: int | None
property message_type: int | None

PortMessage.u2.s2.Type.

property message_type_name: str | None

The LPC_* name of the low byte of the message type.

property owner_port: int
property owner_port_kind: str | None

The WinDbg port type name of the owner port.

property pointers: Record

The pointer fields of the message in this build, by snake_case name.

property port_queue: int

The port whose queue holds the message.

property port_queue_kind: str | None
property port_queue_owner: int | None

The _EPROCESS that owns the queue port.

property port_queue_owner_name: str | None
property queue_port_type: int | None

The QueuePortType bits of u1.State.

property queue_type: int | None

The QueueType bits of u1.State.

property sequence_no: int | None
property state: int | None

u1.State.

property state_flags: list[str]

The PDB names of the one-bit u1.s1 state flags that are set.

property total_length: int | None