ZombieProcess

final class ntoseye.ZombieProcess

Subclass of BaseRecord.

An exited process whose object still has references.

property eprocess: int
property exit_status: int

The exit NTSTATUS.

property exit_time: int

_EPROCESS.ExitTime, a FILETIME.

property handle_count: int

Open handles to the object.

property image: str

The image name.

property pid: int
property pointer_count: int

References to the object.