NtHeapEntry

final class ntoseye.NtHeapEntry

Subclass of BaseRecord.

An NT-heap entry (_HEAP_ENTRY), decoded from its header.

property address: int

The entry header.

property checksum_ok: bool

Whether the XOR checksum of the header is correct. Always true if the headers are not encoded.

property flags: int

The flags byte of the header.

property granule: int

The header size in bytes (see NtHeap.granule).

property kind: str

Always entry.

property lfh: NtLfhUserBlocks | None

The legacy-LFH user block region in this busy entry. None if the entry has no region or ntoseye cannot read it. Also None in a Heaps.find_block() result, because find_block() does not decode the region.

property lfh_error: str | None

The reason that ntoseye could not read the LFH region of the entry.

property lfh_truncated: bool

Whether the blocks list of the region stops at the walk limit.

property previous_size: int

The size in bytes of the previous entry.

property size: int

The size in bytes, with the header.

property state: str

busy or free.

property unused_bytes: int

The number of unused bytes at the end of the block.

property user: int

First user byte.

property user_size: int

The number of bytes that the caller requested: the block size minus the header and the unused bytes.