Peb¶
- final class ntoseye.Peb¶
Subclass of
BaseRecord.A process’s
_PEB(!peb). ntoseye reads each field separately.- property api_set_map: Diagnostic[int]¶
The API set schema.
- property being_debugged: Diagnostic[int]¶
BeingDebugged: nonzero while a user-mode debugger is attached.
- property image_base_address: Diagnostic[int]¶
- property ldr: Diagnostic[int]¶
The
_PEB_LDR_DATAaddress.
- property loader_lists: Diagnostic[LoaderLists]¶
The loader’s module list heads.
- property number_of_heaps: Diagnostic[int]¶
- property number_of_processors: Diagnostic[int]¶
- property os_build_number: Diagnostic[int]¶
- property os_major_version: Diagnostic[int]¶
- property os_minor_version: Diagnostic[int]¶
- property process_heap: Diagnostic[int]¶
The default heap.
- property process_heaps: Diagnostic[int]¶
The heap pointer array.
- property process_parameters: Diagnostic[int]¶
The
_RTL_USER_PROCESS_PARAMETERSaddress.
- property process_parameters_detail: Diagnostic[ProcessParameters]¶
The decoded process parameters.
- property session_id: Diagnostic[int]¶