ImageSectionCheck

final class ntoseye.ImageSectionCheck

Subclass of BaseRecord.

The comparison of one executable section with the cached image.

property genuine_mismatches: int

The number of mismatched bytes, without known self-patches.

property name: str
property rva: int
property self_patches: ImageSelfPatchCounts
property skip_reason: str | None

The reason for the skip. None if ntoseye compared the section.

property skipped: bool

Whether ntoseye skipped the comparison of this section.

property total_mismatches: int

The number of mismatched bytes, with known self-patches.

property unavailable: str | None

The reason that ntoseye could not read the section memory. None if the read succeeded.