RunStatus

final class ntoseye.RunStatus

Subclass of BaseRecord.

Whether the target runs, and where it stopped.

property attached_process: ProcessIdentity | None

The process that you selected with .process. dt, dq, and similar commands read its memory, and the selection stays after the target resumes.

property coherent: bool

False after a reboot until the kernel’s loaded-module list exists, and process and module enumeration is not valid until then.

property current_thread: str

The selected backend thread/vCPU.

property kernel_base: int

The nt base that ntoseye found again. It changes across a reboot.

property partition: int | None

The hypervisor partition whose Windows guest is inspected in place of the target (.partition), or None while the target is. Every other field is then that guest’s.

property rip: int | None

The instruction pointer when halted. None while the target runs.

property running: bool
property running_vp: str | None

The guest partition’s virtual processor that the halted vCPU runs (partition 0x5 VP 2), whose registers and code the vCPU then shows, or None.

property saved_vtl: list[SavedVtlState]

For a vCPU halted in the Windows hypervisor, the VTL states that the hypervisor saved for the vCPU’s virtual processor, VTL0 first.

property serving: ServedVp | None

For a vCPU halted in the Windows hypervisor, the guest partition’s virtual processor it serves, as VcpuStatus.serving.

property stopped_process: ProcessIdentity | None

The process whose page tables the stopped vCPU has loaded.

property stopped_thread: ThreadSummary | None

The Windows thread that the stopped vCPU runs. Its owner can be different from stopped_process (KeStackAttachProcess).

property symbol: str | None

The nearest symbol to rip when halted. For code outside NT, the name identifies that code (hv+0x3a6bde).