Contents Menu Expand Light mode Dark mode Auto light/dark, in light mode Auto light/dark, in dark mode Skip to content
ntoseye
Logo
ntoseye

Getting started

  • Install
  • Quickstart
  • Tutorial: a first session
  • Coming from WinDbg
  • Troubleshooting
  • Command line

Setting up a target

  • Choosing a backend
  • KVM/QEMU
  • VMware Workstation
  • UTM (macOS, Apple Silicon)
  • KDNET

Using ntoseye

  • Using the REPL
  • Breakpoints and watchpoints
  • Memory and paging
  • Symbols and source
  • Crash dumps
  • Driver replacement map (.kdfiles)

Platform topics

  • VBS and the Windows hypervisor
  • WOW64 processes

Integrations

  • Editor integration (DAP)
  • Disassembler integration (GDB remote protocol)
  • MCP integration

Scripting

  • Python SDK
  • Custom REPL commands
  • Python API
    • AddressModule
    • Breakpoint
    • BreakpointIterator
    • Breakpoints
    • Cpu
    • CpuIterator
    • Cpus
    • Debugger
    • Device
    • Diagnostic
    • Driver
    • DriverIterator
    • Drivers
    • Exceptions
    • Export
    • Field
    • Frame
    • Heap
    • HeapIterator
    • Heaps
    • Inspect
    • Memory
    • MemoryRegion
    • MemoryRegionIterator
    • MemorySearchMatch
    • Module
    • ModuleIterator
    • Modules
    • Msrs
    • NameIterator
    • Process
    • Processes
    • ProcessIterator
    • Record
    • RecordIterator
    • Regions
    • Registers
    • Section
    • SecureKernel
    • Stop
    • Struct
    • Symbol
    • Symbols
    • Thread
    • ThreadIterator
    • Threads
    • Trustlet
    • Type
    • Types
    • Watchpoint

Reference

  • Commands
    • Execution and stack
    • Breakpoints and events
    • Memory and disassembly
    • Symbols, types, and expressions
    • Processes and modules
    • User mode
    • CPU
    • Memory manager
    • Objects and I/O
    • Security
    • Analysis
    • Target control
    • Session
  • Expressions

Internals

  • VBS internals
  • Reading memory over KD
  • Rust crate API (docs.rs)

Resources

  • Source code
  • Releases
  • Bug reports
  • Discussions
  • PyPI package
  • crates.io
Back to top
View this page
Edit this page

Regions¶

final class ntoseye.Regions¶

A process’s VAD region collection (!vad).

__contains__(addr: int, /) → bool¶
__getitem__(addr: int, /) → MemoryRegion¶
__iter__() → MemoryRegionIterator¶
__len__() → int¶
at(addr: int) → MemoryRegion | None¶

Find the VAD region containing addr, or return None.

Next
Registers
Previous
RecordIterator
Copyright © dmaivel
Made with Sphinx and @pradyunsg's Furo
On this page
  • Regions
    • Regions
      • Regions.__contains__()
      • Regions.__getitem__()
      • Regions.__iter__()
      • Regions.__len__()
      • Regions.at()