HeapMatchNtLfhBlock

final class ntoseye.HeapMatchNtLfhBlock

Subclass of BaseRecord.

An address inside a legacy-LFH block of an NT heap.

property address: int
property entry: NtHeapEntry

The busy entry that contains the region.

property index: int

The position of the block in the region.

property kind: str

Always nt-lfh-block.

property region: NtLfhUserBlocks

The user block region. Its blocks list is empty.

property segment: int

The _HEAP_SEGMENT that contains the region.

property size: int

Bytes per block.

property state: str

busy or free.

property user: int

First user byte.