HypercallCaller¶
- final class ntoseye.HypercallCaller¶
The virtual processor whose hypercall a processor halted in the Windows hypervisor handles (
cpu.hypercall_caller()), found as!hvcalland a hypercall breakpoint’s filter find it: the call as the caller made it, and the caller’s memory, which a hypercall breakpoint’s condition reads.- property hypercall: DecodedHypercall | None¶
The call with its input decoded, as
!hvcallshows it, orNonewhen the caller’s registers are not known.
- read(address: int, size: int, physical: bool = False) bytes¶
Read
sizebytes of the caller’s memory, as a hypercall breakpoint’s condition reads it: guest virtual memory through the calling VTL’s page tables (its CR3), or withphysical=Trueguest physical memory (a slow call’s input, at the GPA inrdx), both through its EPT. The memory is read now, so read it while the target is halted at the call. RaisesNtoseyeErrorwhen the caller’s state at the call is not known, when a page is not mapped, and for a virtual address unless the caller is in 4-level long-mode paging. The memory is read-only.
- property registers: dict[str, int]¶
The caller’s registers at its VMCALL by name (
rcx,rdx,r8,rip,cr3, …), as a hypercall breakpoint’s condition sees them: RIP, RSP, flags, control and segment registers from the calling VTL’s eVMCS, and the general-purpose registers when ntoseye recovered them. Empty when the state ntoseye found is an older exit’s.
- property root: bool¶
Whether the caller is a VP of the root partition (Windows itself) rather than of a guest partition.