NtHeapEntry¶
- final class ntoseye.NtHeapEntry¶
Subclass of
BaseRecord.An NT-heap entry (
_HEAP_ENTRY), decoded from its header.- property checksum_ok: bool¶
Whether the XOR checksum of the header is correct. Always true if the headers are not encoded.
- property lfh: NtLfhUserBlocks | None¶
The legacy-LFH user block region in this busy entry.
Noneif the entry has no region or ntoseye cannot read it. AlsoNonein aHeaps.find_block()result, becausefind_block()does not decode the region.