ThreadSummary

final class ntoseye.ThreadSummary

Subclass of BaseRecord.

A Windows thread, as threads, !thread, and all scheduler listings show it. A field that the walk could not read is None.

property active: str | None

The vCPU that runs the thread, if the listing resolves it. None if no vCPU runs it, and while the target runs.

property eprocess: int | None

The owning _EPROCESS.

property ethread: int
property kthread: int
property pid: int | None
property priority: int | None

The current scheduling priority.

property process_name: str | None

The image name of the owning process.

property state: int | None

_KTHREAD.State.

property state_name: str | None

The name of the state (Running, Waiting, …).

property tid: int | None
property wait_reason: int | None

_KTHREAD.WaitReason.

property wait_reason_name: str | None

The name of the wait reason (Executive, UserRequest, …).