InFlightIrp

final class ntoseye.InFlightIrp

Subclass of BaseRecord.

An in-flight IRP that ntoseye found on the IrpList of a thread or in the CurrentIrp of a device (irps).

property current_location: int
property device: int | None

The device of the current stack location. None if ntoseye cannot resolve it.

property driver: str | None

The driver that owns the device of the current stack location. None if ntoseye cannot resolve it.

property ethread: int | None
property irp: int
property pid: int | None

The process that issued the IRP. None if ntoseye found the IRP on a device.

property source: str

Where ntoseye found the IRP: thread or device.

property stack_count: int
property state: str | None

The state name of the thread. None if ntoseye found the IRP on a device.

property tid: int | None

The thread that issued the IRP. None if ntoseye found the IRP on a device.

property wait_reason: str | None

The wait-reason name of the thread. None if ntoseye found the IRP on a device.