MemoryBasicInformation

final class ntoseye.MemoryBasicInformation

Subclass of BaseRecord.

The data that VirtualQuery reports for an address (!vprot). Each MEM_*/PAGE_* value has its name next to it.

property address: int
property allocation_base: int

The VAD’s start; zero for free memory.

property allocation_protect: int
property allocation_protect_name: str
property base_address: int
property process: ProcessIdentity
property protect: int
property protect_name: str
property region_size: int

The number of bytes from base_address to the first page with a different state or protection, or to the end of the VAD.

property state: int
property state_name: str
property truncated: bool

Whether the scan stopped before the end of the region, at its limit or at a page table that it cannot read. If true, region_size is a lower bound.

property type: int
property type_name: str
property vad: int | None

The VAD node; None for free memory.