LoaderModule

final class ntoseye.LoaderModule

Subclass of BaseRecord.

One module on a process’s loader list (!dlls).

property base_address: int
property checksum: int | None

The checksum from the PE header. None if ntoseye cannot read the header.

property entry_point: int | None

The entry point. None if the loader entry has no entry point or ntoseye cannot read it.

property file_version: str | None

The file version from the version resource. None if ntoseye cannot read it.

property is_32bit: bool

Whether the module is on the WOW64 (32-bit) loader list.

property name: str

The full path.

property product_version: str | None

The product version from the version resource. None if ntoseye cannot read it.

property short_name: str

The file name.

property size: int

The image size in bytes.

property time_date_stamp: int | None

The link timestamp from the PE header. None if ntoseye cannot read the header.