Amd64TrapFrame

final class ntoseye.Amd64TrapFrame

Subclass of BaseRecord.

The x64 registers that a _KTRAP_FRAME saved. A register is None if the entry that built the frame does not write it. The nonvolatile registers r12-r15 are in the _KEXCEPTION_FRAME, so this type does not include them.

property cs: int
property eflags: int
property error_code: int | None

The exception error code, which is stale for a vector that has no error code.

property kind: str | None

The entry that built the frame: interrupt, exception, system call, or Zw call. None if the entry is unknown, and then only the machine frame and rbp are reliable.

property previous_irql: int | None

The IRQL before the trap, which only interrupts record.

property previous_mode: int

The mode that the trap came from: 0 for kernel, 1 for user.

property r10: int | None
property r11: int | None
property r8: int | None
property r9: int | None
property rax: int | None
property rbp: int
property rbx: int | None
property rcx: int | None
property rdi: int | None
property rdx: int | None
property rip: int
property rsi: int | None
property rsp: int
property ss: int | None