DecodedHypercall¶
- final class ntoseye.DecodedHypercall¶
Subclass of
BaseRecord.The hypercall of a VMCALL exit, with its input decoded as the Hyper-V TLFS lays it out (
!hvcall).- property decoded: bool¶
Whether ntoseye knows the layout of the call’s input. When it does not,
fieldsholds the input as raw qwords: RDX and R8 for a fast call, else the first 8 qwords of the input.
- property elements: list[HypercallElement]¶
A rep call’s input list, each element up to the rep count.
- property fast: bool¶
Whether the input is in registers (RDX, R8, and XMM0 to XMM5) rather than in memory.
- property fields: list[HypercallField]¶
- property input_gpa: int | None¶
The guest physical address of the input (RDX), for a call whose input is in memory.
- property output_gpa: int | None¶
The guest physical address of the output (R8), for a call whose input is in memory.
Why some of the input is missing: an unreadable input page, input in XMM registers, or input past the end of its page.