GlobalFlags

final class ntoseye.GlobalFlags

Subclass of BaseRecord.

nt!NtGlobalFlag and the _PEB.NtGlobalFlag of the current process (!gflag).

property kernel: int

nt!NtGlobalFlag.

property kernel_address: int

The address of nt!NtGlobalFlag.

property kernel_flags: list[GlobalFlag]
property process: ProcessIdentity | None

The current process. None if no process is selected.

property process_flags: Diagnostic[ProcessGlobalFlags]

The flags of the current process, read from its PEB.