ZombieThread

final class ntoseye.ZombieThread

Subclass of BaseRecord.

A terminated thread whose object still has references.

property ethread: int
property exit_status: int

The exit NTSTATUS.

property handle_count: int

Open handles to the object.

property image: str | None

The image name of the owning process. None if ntoseye cannot read it.

property pid: int
property pointer_count: int

References to the object.

property process: int

The owning _EPROCESS.

property tid: int