Peb32

final class ntoseye.Peb32

Subclass of BaseRecord.

A WOW64 process’s 32-bit _PEB32. ntoseye reads each field separately.

property address: int
property being_debugged: Diagnostic[int]

BeingDebugged: nonzero while a user-mode debugger is attached.

property image_base_address: Diagnostic[int]
property ldr: Diagnostic[int]

The _PEB_LDR_DATA32 address.

property loader_lists: Diagnostic[LoaderLists]

The loader’s 32-bit module list heads.

property number_of_heaps: Diagnostic[int]
property number_of_processors: Diagnostic[int]
property os_build_number: Diagnostic[int]
property os_major_version: Diagnostic[int]
property os_minor_version: Diagnostic[int]
property process_heap: Diagnostic[int]

The default heap.

property process_heaps: Diagnostic[int]

The heap pointer array.

property process_parameters: Diagnostic[int]

The 32-bit process parameters’ address.

property process_parameters_detail: Diagnostic[ProcessParameters]

The decoded 32-bit process parameters.

property session_id: Diagnostic[int]