Subclass of BaseRecord.
A Windows thread, as threads, !thread, and all scheduler listings
show it. A field that the walk could not read is None.
-
property active: str | None
The vCPU that runs the thread, if the listing resolves it. None if
no vCPU runs it, and while the target runs.
-
property eprocess: int | None
The owning _EPROCESS.
-
property ethread: int
-
property kthread: int
-
property pid: int | None
-
property priority: int | None
The current scheduling priority.
-
property process_name: str | None
The image name of the owning process.
-
property state: int | None
_KTHREAD.State.
-
property state_name: str | None
The name of the state (Running, Waiting, …).
-
property tid: int | None
-
property wait_reason: int | None
_KTHREAD.WaitReason.
-
property wait_reason_name: str | None
The name of the wait reason (Executive, UserRequest, …).