Teb

final class ntoseye.Teb

Subclass of BaseRecord.

A thread’s _TEB (!teb). ntoseye reads each field separately.

property activation_context: Diagnostic[int | None]

The active activation context, or None if there is no active context.

property address: int
property client_id_unique_process: Diagnostic[int]
property client_id_unique_thread: Diagnostic[int]
property count_of_owned_critical_sections: Diagnostic[int]
property last_error_value: Diagnostic[int]

The Win32 last error.

property last_status_value: Diagnostic[int]

The last NTSTATUS.

property peb: Diagnostic[int]

The process’s _PEB.

property stack_base: Diagnostic[int]
property stack_limit: Diagnostic[int]
property teb32: Teb32 | None

The WOW64 _TEB32. None for a native thread.

property tls_pointer: Diagnostic[int]

The thread-local storage array.

property wow64_reserved: Diagnostic[int]

WOW32Reserved: the WOW64 transition thunk.

property wow_teb_offset: Diagnostic[int]

WowTebOffset: the byte offset to the WOW64 _TEB32, or 0 if there is no _TEB32.