AlpcPort

final class ntoseye.AlpcPort

Subclass of BaseRecord.

An _ALPC_PORT (!alpc /p). A field is None if this Windows build does not have it, or if ntoseye cannot read it.

property address: int
property attribute_flags: int | None

PortAttributes.Flags.

property client_port: int | None
property communication_info: int
property completion_list: int | None
property completion_port: int | None
property connection_port: int | None
property connection_termination: ListEnd | None

How the walk of the connection list ended. None if there was no walk.

property connections: list[AlpcConnection]

The connections of a connection port.

property direct_queue_length: int | None
property handle_count: int
property kind: str | None

The WinDbg port type name (ALPC_CONNECTION_PORT, …).

property max_message_length: int | None

PortAttributes.MaxMessageLength.

property name: str | None
property owner: int

The _EPROCESS that owns the port.

property owner_name: str | None
property pointer_count: int
property port_context: int | None
property port_type: int | None

The Type bits of u1.State.

property queues: list[AlpcQueue]
property sequence_no: int | None
property server_port: int | None
property state: int | None

u1.State.

property state_flags: list[str]

The PDB names of the one-bit u1.s1 state flags that are set.