HypervisorVtl

final class ntoseye.HypervisorVtl

One VTL of a virtual processor: the hypervisor’s context for it and, when found, its eVMCS and the guest state saved there.

property context: int

The address of the hypervisor’s context object for this VTL.

disassemble(address: int, count: int, physical: bool = False) → list[DisassembledInstruction]

Disassemble count instructions of this VTL’s guest at address, as !hvu does: read as read reads it (guest virtual, or with physical=True guest physical), and decoded in the mode the VTL left off in, 64-bit in IA-32e mode with a 64-bit code segment, else 32-bit. Branch and RIP-relative comments are addresses: there are no symbols for a guest. The listing stops at the first unreadable page, so it can hold fewer than count instructions. Raises NtoseyeError when the first instruction is unreadable, without the VTL’s eVMCS state, for real-mode or 16-bit code, and for a virtual address unless the guest is in 4-level long-mode paging.

property ept_pointer: int | None

The VTL’s EPT pointer, the root of its second-level address translation, or None without the eVMCS.

property exit_reason: int | None

The basic reason (Intel SDM Appendix C) the VTL last left for the hypervisor, or None without the eVMCS.

io_intercepts() → IoIntercepts

Which I/O instructions of this VTL exit, as !hvvmcs -io shows them: the port ranges its I/O bitmaps intercept, or, when its controls use none, every port (every) or none. Raises NtoseyeError without the VTL’s eVMCS, or when a bitmap is unreadable.

property level: int

The VTL (0 for NT, 1 for the secure kernel).

msr_intercepts() → MsrIntercepts

Which RDMSRs and WRMSRs of this VTL exit, as !hvvmcs -msr shows them: through its MSR bitmap when its controls use one, else every one (every). Each intercepted range names the architectural MSRs in it, and read_without_exit and write_without_exit list those the VTL accesses without an exit. MSRs outside the bitmap’s 0x0-0x1fff and 0xc0000000-0xc0001fff always exit. Raises NtoseyeError without the VTL’s eVMCS, or when the bitmap is unreadable.

read(address: int, size: int, physical: bool = False) → bytes

Read size bytes of the memory of this VTL’s guest, as !hvd does: guest virtual memory through the VTL’s page tables (its saved CR3), or with physical=True guest physical memory, both through the VTL’s EPT. Raises NtoseyeError without the VTL’s eVMCS state or when a page is not mapped, and for a virtual address unless the guest is in 4-level long-mode paging. The memory is read-only.

property rip: int | None

The guest RIP where the VTL left off, or None without the eVMCS.

to_dict() → dict[str, Any]

Return the VTL as a plain dict (level, context, vmcs, ept_pointer, rip, exit_reason).

translate(gpa: int) → EptMapping | None

Translate a guest physical address through this VTL’s EPT, as !hvept does. Returns None when no entry maps it, and raises NtoseyeError without the VTL’s eVMCS state or when a table is unreadable.

translate_virtual(address: int) → tuple[int, int] | None

Translate a guest virtual address of this VTL’s guest through its page tables and its EPT: (guest_physical, host_physical), or None when the page tables do not map it. Raises NtoseyeError unless the guest is in 4-level long-mode paging.

property vmcs: int | None

The physical address of the VTL’s eVMCS, or None when ntoseye did not find where the context keeps it (no hv-evmcs).

vmcs_fields() → Record

Every field of this VTL’s eVMCS, read now, named as the TLFS names it (guest_rip, msr_bitmap, …), as !hvvmcs shows them: fields.guest_rip or fields["guest_rip"]. Raises NtoseyeError without the VTL’s eVMCS.