RunStatus¶
- final class ntoseye.RunStatus¶
Subclass of
BaseRecord.Whether the target runs, and where it stopped.
- property attached_process: ProcessIdentity | None¶
The process that you selected with
.process.dt,dq, and similar commands read its memory, and the selection stays after the target resumes.
- property coherent: bool¶
False after a reboot until the kernel’s loaded-module list exists, and process and module enumeration is not valid until then.
- property partition: int | None¶
The hypervisor partition whose Windows guest is inspected in place of the target (
.partition), or None while the target is. Every other field is then that guest’s.
- property running_vp: str | None¶
The guest partition’s virtual processor that the halted vCPU runs (
partition 0x5 VP 2), whose registers and code the vCPU then shows, or None.
- property saved_vtl: list[SavedVtlState]¶
For a vCPU halted in the Windows hypervisor, the VTL states that the hypervisor saved for the vCPU’s virtual processor, VTL0 first.
- property serving: ServedVp | None¶
For a vCPU halted in the Windows hypervisor, the guest partition’s virtual processor it serves, as
VcpuStatus.serving.
- property stopped_process: ProcessIdentity | None¶
The process whose page tables the stopped vCPU has loaded.
- property stopped_thread: ThreadSummary | None¶
The Windows thread that the stopped vCPU runs. Its owner can be different from
stopped_process(KeStackAttachProcess).