Peb32¶
- final class ntoseye.Peb32¶
Subclass of
BaseRecord.A WOW64 process’s 32-bit
_PEB32. ntoseye reads each field separately.- property being_debugged: Diagnostic[int]¶
BeingDebugged: nonzero while a user-mode debugger is attached.
- property image_base_address: Diagnostic[int]¶
- property ldr: Diagnostic[int]¶
The
_PEB_LDR_DATA32address.
- property loader_lists: Diagnostic[LoaderLists]¶
The loader’s 32-bit module list heads.
- property number_of_heaps: Diagnostic[int]¶
- property number_of_processors: Diagnostic[int]¶
- property os_build_number: Diagnostic[int]¶
- property os_major_version: Diagnostic[int]¶
- property os_minor_version: Diagnostic[int]¶
- property process_heap: Diagnostic[int]¶
The default heap.
- property process_heaps: Diagnostic[int]¶
The heap pointer array.
- property process_parameters: Diagnostic[int]¶
The 32-bit process parameters’ address.
- property process_parameters_detail: Diagnostic[ProcessParameters]¶
The decoded 32-bit process parameters.
- property session_id: Diagnostic[int]¶