Beispiel #1
0
def walkEThreads(db, trace, listva):
    for va, obj in vt_winkern.walkListEntryHead(trace, listva, 'nt.ETHREAD',
                                                'ThreadListEntry'):
        yield va, obj
Beispiel #2
0
def walkEThreads(db,trace,listva):
    for va,obj in vt_winkern.walkListEntryHead(trace,listva,'nt.ETHREAD','ThreadListEntry'):
        yield va,obj
Beispiel #3
0
def walkEprocesses(db, trace):
    dbgdata64 = db.getRunCacheVar('KDDEBUGGER_DATA64')
    phead = dbgdata64.PsActiveProcessHead
    for va, obj in vt_winkern.walkListEntryHead(trace, phead, 'nt.EPROCESS',
                                                'ActiveProcessLinks'):
        yield va, obj
Beispiel #4
0
def walkEprocesses(db,trace):
    dbgdata64 = db.getRunCacheVar('KDDEBUGGER_DATA64')
    phead = dbgdata64.PsActiveProcessHead
    for va,obj in vt_winkern.walkListEntryHead(trace,phead,'nt.EPROCESS','ActiveProcessLinks'):
        yield va,obj