TriageReport

final class ntoseye.TriageReport

Subclass of BaseRecord.

The one-shot crash triage report (!analyze), with the run status, the bugcheck or exception, the backtrace, the modules, the dump records, and the findings.

property backtrace: list[StackFrame] | None

The stack of the current thread. None while the target runs or if the unwind failed (see warnings).

property blackboxes: list[BlackboxStream]
property broken_driver: str | None

The driver that the dump records as broken.

property bugcheck: Bugcheck | None

The bugcheck, if the target is in a bugcheck.

property crash_context: CrashContext | None

The process and thread that crashed, as a triage dump recorded them.

property culprit: Culprit | None

The module that the evidence identifies as the cause. None if the evidence does not identify a non-kernel module.

property exception: DumpException | None

The exception that a dump recorded.

property failure_signature: FailureSignature | None
property modules: list[LoadedModule]

The loaded modules, up to a maximum that the caller sets (see modules_total).

property modules_total: int

The number of loaded modules.

property prcb: TriagePrcb | None

The processor that crashed, as a triage dump recorded it.

property status: RunStatus

The target’s run status.

property system_info: DumpSystemInfo | None

The system information of the dump.

property triage_overflowed: bool | None

True if the triage data of the dump overflowed. None if the target is not a dump.

property unloaded_drivers: list[UnloadedDriver]
property verifier: VerifierFinding | None

The Driver Verifier violation of a verifier bugcheck.

property warnings: list[str]

Failures in best-effort data collection that did not stop the report.

property whea: WheaFinding | None

The hardware error record of a WHEA bugcheck.