NtHeap

final class ntoseye.NtHeap

Subclass of BaseRecord.

An NT (_HEAP) heap.

property address: int
property encoding: int | None

The XOR mask on the metadata of each entry header. None if the headers are not encoded.

property flags: int

_HEAP.Flags.

property force_flags: int

_HEAP.ForceFlags.

property front_end: int | None

The front-end (LFH) heap. None if the heap has no front end.

property front_end_type: int

_HEAP.FrontEndHeapType.

property granule: int

The size in bytes of the _HEAP_ENTRY that starts each block: 16 on x64, 8 on x86.

property segments: list[NtHeapSegment]
property total_free_units: int

The free space, in granules.

property virtual_blocks: list[NtVirtualBlock]

Blocks that are too large for a segment, which the heap allocates separately.

property virtual_threshold: int

_HEAP.VirtualMemoryThreshold, in granules.