LoadedModule

final class ntoseye.LoadedModule

Subclass of BaseRecord.

A loaded image (lm).

property base: int
property checksum: int | None

The PE checksum. None if the loader record does not contain one.

property end: int

The address after the last byte of the image.

property file_version: str | None

The file version from the version resource. None if ntoseye did not read it.

property name: str

The image file name (ntoskrnl.exe).

property path: str | None

The full image path, if the loader recorded one.

property product_version: str | None

The product version from the version resource. None if ntoseye did not read it.

property short_name: str

The short name that module!symbol uses (nt).

property size: int

The mapped image size in bytes.

property symbols: ModuleSymbols | None

The symbol status. None except in inspect() of a kernel module.

property time_date_stamp: int | None

The PE timestamp. None if the loader record does not contain one.