Min version | 2003/XP64 SP1 | Vista SP1 | Vista SP2 | Vista SP2 | 7 | 7 SP1 | 7 SP1 | 7 SP1 | 8 Pre RTM | 8 | 8.1 | 8.1 Update 1 | 8.1 Update 1 | 10 Pre RTM | 10 Pre RTM | 10 | 10 TH2 |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Max version | 2003/XP64 SP2 | 7 SP1 | 8.1 Update 1 | ||||||||||||||
x64 offset offset:bitpos | Field Name | ||||||||||||||||
0x0000 | struct _KPROCESS Pcb | struct _KPROCESS Pcb | struct _KPROCESS Pcb | struct _KPROCESS Pcb | struct _KPROCESS Pcb | struct _KPROCESS Pcb | struct _KPROCESS Pcb | ||||||||||
0x00B8 | struct _EX_PUSH_LOCK ProcessLock | ||||||||||||||||
0x00C0 | union _LARGE_INTEGER CreateTime | struct _EX_PUSH_LOCK ProcessLock | |||||||||||||||
0x00C8 | union _LARGE_INTEGER ExitTime | union _LARGE_INTEGER CreateTime | |||||||||||||||
0x00D0 | struct _EX_RUNDOWN_REF RundownProtect | union _LARGE_INTEGER ExitTime | |||||||||||||||
0x00D8 | void * UniqueProcessId | struct _EX_RUNDOWN_REF RundownProtect | |||||||||||||||
0x00E0 | struct _LIST_ENTRY ActiveProcessLinks | void * UniqueProcessId | |||||||||||||||
0x00E8 | struct _LIST_ENTRY ActiveProcessLinks | ||||||||||||||||
0x00F0 | uint64_t[3] QuotaUsage | ||||||||||||||||
0x00F8 | uint64_t[3] QuotaUsage | ||||||||||||||||
0x0108 | uint64_t[3] QuotaPeak | ||||||||||||||||
0x0110 | uint64_t[3] QuotaPeak | ||||||||||||||||
0x0120 | uint64_t CommitCharge | ||||||||||||||||
0x0128 | uint64_t PeakVirtualSize | volatile uint64_t CommitCharge | |||||||||||||||
0x0130 | uint64_t VirtualSize | uint64_t PeakVirtualSize | |||||||||||||||
0x0138 | struct _LIST_ENTRY SessionProcessLinks | uint64_t VirtualSize | |||||||||||||||
0x0140 | struct _LIST_ENTRY SessionProcessLinks | ||||||||||||||||
0x0148 | void * DebugPort | ||||||||||||||||
0x0150 | void * ExceptionPort | void * DebugPort | |||||||||||||||
0x0158 | struct _HANDLE_TABLE * ObjectTable | void * ExceptionPortData | |||||||||||||||
0x0158 | uint64_t ExceptionPortValue | ||||||||||||||||
0x0158:0x00 | uint64_t ExceptionPortState | ||||||||||||||||
0x0160 | struct _EX_FAST_REF Token | struct _HANDLE_TABLE * ObjectTable | struct _EX_PUSH_LOCK ProcessLock | ||||||||||||||
0x0168 | uint64_t WorkingSetPage | struct _EX_FAST_REF Token | union _LARGE_INTEGER CreateTime | ||||||||||||||
0x0170 | struct _KGUARDED_MUTEX AddressCreationLock | uint64_t WorkingSetPage | union _LARGE_INTEGER ExitTime | ||||||||||||||
0x0178 | struct _EX_PUSH_LOCK AddressCreationLock | struct _EX_RUNDOWN_REF RundownProtect | |||||||||||||||
0x0180 | struct _ETHREAD * RotateInProgress | void * UniqueProcessId | |||||||||||||||
0x0188 | struct _ETHREAD * ForkInProgress | struct _LIST_ENTRY ActiveProcessLinks | |||||||||||||||
0x0190 | uint64_t HardwareTrigger | ||||||||||||||||
0x0198 | struct _MM_AVL_TABLE * PhysicalVadRoot | uint64_t[2] ProcessQuotaUsage | |||||||||||||||
0x01A0 | void * CloneRoot | ||||||||||||||||
0x01A8 | uint64_t HyperSpaceLock | volatile uint64_t NumberOfPrivatePages | uint64_t[2] ProcessQuotaPeak | ||||||||||||||
0x01B0 | struct _ETHREAD * ForkInProgress | volatile uint64_t NumberOfLockedPages | |||||||||||||||
0x01B8 | uint64_t HardwareTrigger | void * Win32Process | volatile uint64_t CommitCharge | struct _EX_PUSH_LOCK ProcessLock | |||||||||||||
0x01C0 | struct _MM_AVL_TABLE * PhysicalVadRoot | struct _EJOB * Job | struct _EPROCESS_QUOTA_BLOCK * QuotaBlock | union _LARGE_INTEGER CreateTime | |||||||||||||
0x01C8 | void * CloneRoot | void * SectionObject | struct _PS_CPU_QUOTA_BLOCK * CpuQuotaBlock | struct _EX_RUNDOWN_REF RundownProtect | |||||||||||||
0x01D0 | uint64_t NumberOfPrivatePages | void * SectionBaseAddress | uint64_t PeakVirtualSize | void * UniqueProcessId | |||||||||||||
0x01D8 | uint64_t NumberOfLockedPages | struct _EPROCESS_QUOTA_BLOCK * QuotaBlock | uint64_t VirtualSize | struct _LIST_ENTRY ActiveProcessLinks | |||||||||||||
0x01E0 | void * Win32Process | struct _PAGEFAULT_HISTORY * WorkingSetWatch | struct _LIST_ENTRY SessionProcessLinks | ||||||||||||||
0x01E8 | struct _EJOB * Job | void * Win32WindowStation | uint64_t[2] ProcessQuotaUsage | ||||||||||||||
0x01F0 | void * SectionObject | void * InheritedFromUniqueProcessId | void * DebugPort | ||||||||||||||
0x01F8 | void * SectionBaseAddress | void * LdtInformation | void * ExceptionPortData | uint64_t[2] ProcessQuotaPeak | |||||||||||||
0x01F8 | uint64_t ExceptionPortValue | ||||||||||||||||
0x01F8:0x00 | uint64_t ExceptionPortState | ||||||||||||||||
0x0200 | struct _EPROCESS_QUOTA_BLOCK * QuotaBlock | void * Spare | struct _HANDLE_TABLE * ObjectTable | ||||||||||||||
0x0208 | struct _PAGEFAULT_HISTORY * WorkingSetWatch | void * VdmObjects | struct _EX_FAST_REF Token | uint64_t PeakVirtualSize | |||||||||||||
0x0210 | void * Win32WindowStation | void * DeviceMap | uint64_t WorkingSetPage | uint64_t VirtualSize | |||||||||||||
0x0218 | void * InheritedFromUniqueProcessId | void * EtwDataSource | struct _EX_PUSH_LOCK AddressCreationLock | struct _LIST_ENTRY SessionProcessLinks | |||||||||||||
0x0220 | void * LdtInformation | void * FreeTebHint | struct _ETHREAD * RotateInProgress | ||||||||||||||
0x0228 | void * VadFreeHint | struct _HARDWARE_PTE PageDirectoryPte | struct _ETHREAD * ForkInProgress | void * ExceptionPortData | |||||||||||||
0x0228 | uint64_t Filler | uint64_t ExceptionPortValue | |||||||||||||||
0x0228:0x00 | uint64_t ExceptionPortState | ||||||||||||||||
0x0230 | void * VdmObjects | void * Session | uint64_t HardwareTrigger | struct _EX_FAST_REF Token | |||||||||||||
0x0238 | void * DeviceMap | uint8_t[16] ImageFileName | struct _MM_AVL_TABLE * PhysicalVadRoot | uint64_t WorkingSetPage | |||||||||||||
0x0240 | void *[3] Spare0 | void * CloneRoot | struct _EX_PUSH_LOCK AddressCreationLock | ||||||||||||||
0x0248 | struct _LIST_ENTRY JobLinks | volatile uint64_t NumberOfPrivatePages | struct _ETHREAD * RotateInProgress | ||||||||||||||
0x0250 | volatile uint64_t NumberOfLockedPages | struct _ETHREAD * ForkInProgress | |||||||||||||||
0x0258 | struct _HARDWARE_PTE PageDirectoryPte | void * LockedPagesList | void * Win32Process | uint64_t HardwareTrigger | |||||||||||||
0x0258 | uint64_t Filler | ||||||||||||||||
0x0260 | void * Session | struct _LIST_ENTRY ThreadListHead | struct _EJOB * volatile Job | struct _EJOB * volatile CommitChargeJob | |||||||||||||
0x0268 | uint8_t[16] ImageFileName | void * SectionObject | struct _MM_AVL_TABLE * CloneRoot | ||||||||||||||
0x0270 | void * SecurityPort | void * SectionBaseAddress | volatile uint64_t NumberOfPrivatePages | ||||||||||||||
0x0278 | struct _LIST_ENTRY JobLinks | struct _WOW64_PROCESS * Wow64Process | void * Wow64Process | unsigned long Cookie | volatile uint64_t NumberOfLockedPages | ||||||||||||
0x027C | unsigned long Spare8 | ||||||||||||||||
0x0280 | volatile unsigned long ActiveThreads | struct _PAGEFAULT_HISTORY * WorkingSetWatch | void * Win32Process | ||||||||||||||
0x0284 | unsigned long ImagePathHash | ||||||||||||||||
0x0288 | void * LockedPagesList | unsigned long DefaultHardErrorProcessing | void * Win32WindowStation | struct _EJOB * volatile Job | |||||||||||||
0x028C | long LastThreadExitStatus | ||||||||||||||||
0x0290 | struct _LIST_ENTRY ThreadListHead | struct _PEB * Peb | void * InheritedFromUniqueProcessId | void * SectionObject | |||||||||||||
0x0298 | struct _EX_FAST_REF PrefetchTrace | void * LdtInformation | void * SectionBaseAddress | ||||||||||||||
0x02A0 | void * SecurityPort | union _LARGE_INTEGER ReadOperationCount | void * Spare | unsigned long Cookie | |||||||||||||
0x02A8 | struct _WOW64_PROCESS * Wow64Process | union _LARGE_INTEGER WriteOperationCount | uint64_t ConsoleHostProcess | struct _PAGEFAULT_HISTORY * WorkingSetWatch | |||||||||||||
0x02B0 | unsigned long ActiveThreads | union _LARGE_INTEGER OtherOperationCount | void * DeviceMap | void * Win32WindowStation | |||||||||||||
0x02B4 | unsigned long GrantedAccess | ||||||||||||||||
0x02B8 | unsigned long DefaultHardErrorProcessing | union _LARGE_INTEGER ReadTransferCount | void * EtwDataSource | void * InheritedFromUniqueProcessId | |||||||||||||
0x02BC | long LastThreadExitStatus | ||||||||||||||||
0x02C0 | struct _PEB * Peb | union _LARGE_INTEGER WriteTransferCount | void * FreeTebHint | struct _EPROCESS * CreatorProcess | |||||||||||||
0x02C0 | uint64_t ConsoleHostProcess | ||||||||||||||||
0x02C8 | struct _EX_FAST_REF PrefetchTrace | union _LARGE_INTEGER OtherTransferCount | struct _HARDWARE_PTE PageDirectoryPte | struct _PEB * Peb | struct _EX_PUSH_LOCK ProcessLock | ||||||||||||
0x02C8 | uint64_t Filler | ||||||||||||||||
0x02D0 | union _LARGE_INTEGER ReadOperationCount | uint64_t CommitChargeLimit | void * Session | union _LARGE_INTEGER CreateTime | struct _EX_PUSH_LOCK ProcessLock | ||||||||||||
0x02D8 | union _LARGE_INTEGER WriteOperationCount | volatile uint64_t CommitChargePeak | uint8_t[15] ImageFileName | void * AweInfo | struct _EX_RUNDOWN_REF RundownProtect | struct _EX_PUSH_LOCK ProcessLock | |||||||||||
0x02E0 | union _LARGE_INTEGER OtherOperationCount | void * AweInfo | struct _EPROCESS_QUOTA_BLOCK * QuotaBlock | void * UniqueProcessId | struct _EX_RUNDOWN_REF RundownProtect | ||||||||||||
0x02E7 | uint8_t PriorityClass | ||||||||||||||||
0x02E8 | union _LARGE_INTEGER ReadTransferCount | struct _SE_AUDIT_PROCESS_CREATION_INFO SeAuditProcessCreationInfo | struct _LIST_ENTRY JobLinks | struct _HANDLE_TABLE * ObjectTable | struct _LIST_ENTRY ActiveProcessLinks | void * UniqueProcessId | |||||||||||
0x02F0 | union _LARGE_INTEGER WriteTransferCount | struct _MMSUPPORT Vm | void * DebugPort | struct _LIST_ENTRY ActiveProcessLinks | |||||||||||||
0x02F8 | union _LARGE_INTEGER OtherTransferCount | void * LockedPagesList | void * Wow64Process | unsigned long Flags2 | |||||||||||||
0x02F8:0x00 | unsigned long JobNotReallyActive | ||||||||||||||||
0x02F8:0x01 | unsigned long AccountingFolded | ||||||||||||||||
0x02F8:0x02 | unsigned long NewProcessReported | ||||||||||||||||
0x02F8:0x03 | unsigned long ExitProcessReported | ||||||||||||||||
0x02F8:0x04 | unsigned long ReportCommitChanges | ||||||||||||||||
0x02F8:0x05 | unsigned long LastReportMemory | ||||||||||||||||
0x02F8:0x06 | unsigned long NoWakeCharge | unsigned long ForceWakeCharge | |||||||||||||||
0x02F8:0x07 | unsigned long HandleTableRundown | unsigned long CrossSessionCreate | |||||||||||||||
0x02F8:0x08 | unsigned long NeedsHandleRundown | ||||||||||||||||
0x02F8:0x09 | unsigned long RefTraceEnabled | ||||||||||||||||
0x02F8:0x0A | unsigned long NumaAware | unsigned long DisableDynamicCode | |||||||||||||||
0x02F8:0x0B | unsigned long EmptyJobEvaluated | ||||||||||||||||
0x02F8:0x0C | unsigned long DefaultPagePriority | ||||||||||||||||
0x02F8:0x0F | unsigned long PrimaryTokenFrozen | ||||||||||||||||
0x02F8:0x10 | unsigned long ProcessVerifierTarget | ||||||||||||||||
0x02F8:0x11 | unsigned long StackRandomizationDisabled | ||||||||||||||||
0x02F8:0x12 | unsigned long AffinityPermanent | ||||||||||||||||
0x02F8:0x13 | unsigned long AffinityUpdateEnable | ||||||||||||||||
0x02F8:0x14 | unsigned long PropagateNode | ||||||||||||||||
0x02F8:0x15 | unsigned long ExplicitAffinity | ||||||||||||||||
0x02F8:0x16 | unsigned long ProcessExecutionState | ||||||||||||||||
0x02F8:0x18 | unsigned long DisallowStrippedImages | ||||||||||||||||
0x02F8:0x19 | unsigned long HighEntropyASLREnabled | ||||||||||||||||
0x02F8:0x1A | unsigned long ExtensionPointDisable | ||||||||||||||||
0x02F8:0x1B | unsigned long ForceRelocateImages | ||||||||||||||||
0x02F8:0x1C | unsigned long ProcessStateChangeRequest | ||||||||||||||||
0x02F8:0x1E | unsigned long ProcessStateChangeInProgress | ||||||||||||||||
0x02F8:0x1F | unsigned long DisallowWin32kSystemCalls | ||||||||||||||||
0x02FC | unsigned long Flags | ||||||||||||||||
0x02FC:0x00 | unsigned long CreateReported | ||||||||||||||||
0x02FC:0x01 | unsigned long NoDebugInherit | ||||||||||||||||
0x02FC:0x02 | unsigned long ProcessExiting | ||||||||||||||||
0x02FC:0x03 | unsigned long ProcessDelete | ||||||||||||||||
0x02FC:0x04 | unsigned long Wow64SplitPages | unsigned long ControlFlowGuardEnabled | |||||||||||||||
0x02FC:0x05 | unsigned long VmDeleted | ||||||||||||||||
0x02FC:0x06 | unsigned long OutswapEnabled | ||||||||||||||||
0x02FC:0x07 | unsigned long Outswapped | ||||||||||||||||
0x02FC:0x08 | unsigned long ForkFailed | unsigned long Spare1 | |||||||||||||||
0x02FC:0x09 | unsigned long Wow64VaSpace4Gb | ||||||||||||||||
0x02FC:0x0A | unsigned long AddressSpaceInitialized | ||||||||||||||||
0x02FC:0x0C | unsigned long SetTimerResolution | ||||||||||||||||
0x02FC:0x0D | unsigned long BreakOnTermination | ||||||||||||||||
0x02FC:0x0E | unsigned long DeprioritizeViews | ||||||||||||||||
0x02FC:0x0F | unsigned long WriteWatch | ||||||||||||||||
0x02FC:0x10 | unsigned long ProcessInSession | ||||||||||||||||
0x02FC:0x11 | unsigned long OverrideAddressSpace | ||||||||||||||||
0x02FC:0x12 | unsigned long HasAddressSpace | ||||||||||||||||
0x02FC:0x13 | unsigned long LaunchPrefetched | ||||||||||||||||
0x02FC:0x14 | unsigned long Background | ||||||||||||||||
0x02FC:0x15 | unsigned long VmTopDown | ||||||||||||||||
0x02FC:0x16 | unsigned long ImageNotifyDone | ||||||||||||||||
0x02FC:0x17 | unsigned long PdeUpdateNeeded | ||||||||||||||||
0x02FC:0x18 | unsigned long VdmAllowed | ||||||||||||||||
0x02FC:0x19 | unsigned long CrossSessionCreate | unsigned long ProcessRundown | |||||||||||||||
0x02FC:0x1A | unsigned long ProcessInserted | ||||||||||||||||
0x02FC:0x1B | unsigned long DefaultIoPriority | ||||||||||||||||
0x02FC:0x1E | unsigned long ProcessSelfDelete | ||||||||||||||||
0x02FC:0x1F | unsigned long SetTimerResolutionLink | ||||||||||||||||
0x0300 | uint64_t CommitChargeLimit | struct _LIST_ENTRY ThreadListHead | void * DeviceMap | uint64_t[2] ProcessQuotaUsage | union _LARGE_INTEGER CreateTime | unsigned long Flags2 | |||||||||||
0x0300:0x00 | unsigned long JobNotReallyActive | ||||||||||||||||
0x0300:0x01 | unsigned long AccountingFolded | ||||||||||||||||
0x0300:0x02 | unsigned long NewProcessReported | ||||||||||||||||
0x0300:0x03 | unsigned long ExitProcessReported | ||||||||||||||||
0x0300:0x04 | unsigned long ReportCommitChanges | ||||||||||||||||
0x0300:0x05 | unsigned long LastReportMemory | ||||||||||||||||
0x0300:0x06 | unsigned long ForceWakeCharge | ||||||||||||||||
0x0300:0x07 | unsigned long CrossSessionCreate | ||||||||||||||||
0x0300:0x08 | unsigned long NeedsHandleRundown | ||||||||||||||||
0x0300:0x09 | unsigned long RefTraceEnabled | ||||||||||||||||
0x0300:0x0A | unsigned long DisableDynamicCode | ||||||||||||||||
0x0300:0x0B | unsigned long EmptyJobEvaluated | ||||||||||||||||
0x0300:0x0C | unsigned long DefaultPagePriority | ||||||||||||||||
0x0300:0x0F | unsigned long PrimaryTokenFrozen | ||||||||||||||||
0x0300:0x10 | unsigned long ProcessVerifierTarget | ||||||||||||||||
0x0300:0x11 | unsigned long StackRandomizationDisabled | ||||||||||||||||
0x0300:0x12 | unsigned long AffinityPermanent | ||||||||||||||||
0x0300:0x13 | unsigned long AffinityUpdateEnable | ||||||||||||||||
0x0300:0x14 | unsigned long PropagateNode | ||||||||||||||||
0x0300:0x15 | unsigned long ExplicitAffinity | ||||||||||||||||
0x0300:0x16 | unsigned long ProcessExecutionState | ||||||||||||||||
0x0300:0x18 | unsigned long DisallowStrippedImages | ||||||||||||||||
0x0300:0x19 | unsigned long HighEntropyASLREnabled | ||||||||||||||||
0x0300:0x1A | unsigned long ExtensionPointDisable | ||||||||||||||||
0x0300:0x1B | unsigned long ForceRelocateImages | ||||||||||||||||
0x0300:0x1C | unsigned long ProcessStateChangeRequest | ||||||||||||||||
0x0300:0x1E | unsigned long ProcessStateChangeInProgress | ||||||||||||||||
0x0300:0x1F | unsigned long DisallowWin32kSystemCalls | ||||||||||||||||
0x0304 | unsigned long Flags | ||||||||||||||||
0x0304:0x00 | unsigned long CreateReported | ||||||||||||||||
0x0304:0x01 | unsigned long NoDebugInherit | ||||||||||||||||
0x0304:0x02 | unsigned long ProcessExiting | ||||||||||||||||
0x0304:0x03 | unsigned long ProcessDelete | ||||||||||||||||
0x0304:0x04 | unsigned long ControlFlowGuardEnabled | ||||||||||||||||
0x0304:0x05 | unsigned long VmDeleted | ||||||||||||||||
0x0304:0x06 | unsigned long OutswapEnabled | ||||||||||||||||
0x0304:0x07 | unsigned long Outswapped | ||||||||||||||||
0x0304:0x08 | unsigned long FailFastOnCommitFail | ||||||||||||||||
0x0304:0x09 | unsigned long Wow64VaSpace4Gb | ||||||||||||||||
0x0304:0x0A | unsigned long AddressSpaceInitialized | ||||||||||||||||
0x0304:0x0C | unsigned long SetTimerResolution | ||||||||||||||||
0x0304:0x0D | unsigned long BreakOnTermination | ||||||||||||||||
0x0304:0x0E | unsigned long DeprioritizeViews | ||||||||||||||||
0x0304:0x0F | unsigned long WriteWatch | ||||||||||||||||
0x0304:0x10 | unsigned long ProcessInSession | ||||||||||||||||
0x0304:0x11 | unsigned long OverrideAddressSpace | ||||||||||||||||
0x0304:0x12 | unsigned long HasAddressSpace | ||||||||||||||||
0x0304:0x13 | unsigned long LaunchPrefetched | ||||||||||||||||
0x0304:0x14 | unsigned long Background | ||||||||||||||||
0x0304:0x15 | unsigned long VmTopDown | ||||||||||||||||
0x0304:0x16 | unsigned long ImageNotifyDone | ||||||||||||||||
0x0304:0x17 | unsigned long PdeUpdateNeeded | ||||||||||||||||
0x0304:0x18 | unsigned long VdmAllowed | ||||||||||||||||
0x0304:0x19 | unsigned long ProcessRundown | ||||||||||||||||
0x0304:0x1A | unsigned long ProcessInserted | ||||||||||||||||
0x0304:0x1B | unsigned long DefaultIoPriority | ||||||||||||||||
0x0304:0x1E | unsigned long ProcessSelfDelete | ||||||||||||||||
0x0304:0x1F | unsigned long SetTimerResolutionLink | ||||||||||||||||
0x0308 | uint64_t CommitChargePeak | void * EtwDataSource | uint64_t[2] ProcessQuotaUsage | union _LARGE_INTEGER CreateTime | |||||||||||||
0x0310 | void * AweInfo | void * SecurityPort | struct _HARDWARE_PTE PageDirectoryPte | uint64_t[2] ProcessQuotaPeak | uint64_t[2] ProcessQuotaUsage | ||||||||||||
0x0310 | uint64_t Filler | ||||||||||||||||
0x0318 | struct _SE_AUDIT_PROCESS_CREATION_INFO SeAuditProcessCreationInfo | void * Wow64Process | uint8_t[15] ImageFileName | uint64_t[2] ProcessQuotaPeak | |||||||||||||
0x0320 | struct _MMSUPPORT Vm | volatile unsigned long ActiveThreads | uint64_t PeakVirtualSize | uint64_t[2] ProcessQuotaPeak | |||||||||||||
0x0324 | unsigned long ImagePathHash | ||||||||||||||||
0x0327 | uint8_t PriorityClass | ||||||||||||||||
0x0328 | unsigned long DefaultHardErrorProcessing | void * SecurityPort | uint64_t VirtualSize | uint64_t PeakVirtualSize | |||||||||||||
0x032C | long LastThreadExitStatus | ||||||||||||||||
0x0330 | struct _PEB * Peb | struct _SE_AUDIT_PROCESS_CREATION_INFO SeAuditProcessCreationInfo | struct _LIST_ENTRY SessionProcessLinks | uint64_t VirtualSize | uint64_t PeakVirtualSize | ||||||||||||
0x0338 | struct _EX_FAST_REF PrefetchTrace | struct _LIST_ENTRY JobLinks | struct _LIST_ENTRY SessionProcessLinks | uint64_t VirtualSize | |||||||||||||
0x0340 | union _LARGE_INTEGER ReadOperationCount | void * ExceptionPortData | struct _LIST_ENTRY SessionProcessLinks | ||||||||||||||
0x0340 | uint64_t ExceptionPortValue | ||||||||||||||||
0x0340:0x00 | uint64_t ExceptionPortState | ||||||||||||||||
0x0348 | union _LARGE_INTEGER WriteOperationCount | void * HighestUserAddress | struct _EX_FAST_REF Token | void * ExceptionPortData | |||||||||||||
0x0348 | uint64_t ExceptionPortValue | ||||||||||||||||
0x0348:0x00 | uint64_t ExceptionPortState | ||||||||||||||||
0x0350 | union _LARGE_INTEGER OtherOperationCount | struct _LIST_ENTRY ThreadListHead | uint64_t WorkingSetPage | struct _EX_FAST_REF Token | void * ExceptionPortData | ||||||||||||
0x0350 | uint64_t ExceptionPortValue | ||||||||||||||||
0x0350:0x00 | uint64_t ExceptionPortState | ||||||||||||||||
0x0358 | struct _LIST_ENTRY MmProcessLinks | union _LARGE_INTEGER ReadTransferCount | struct _EX_PUSH_LOCK AddressCreationLock | uint64_t WorkingSetPage | struct _EX_FAST_REF Token | ||||||||||||
0x0360 | union _LARGE_INTEGER WriteTransferCount | volatile unsigned long ActiveThreads | struct _ETHREAD * RotateInProgress | struct _EX_PUSH_LOCK PageTableCommitmentLock | struct _EX_PUSH_LOCK AddressCreationLock | uint64_t WorkingSetPage | |||||||||||
0x0364 | unsigned long ImagePathHash | ||||||||||||||||
0x0368 | unsigned long ModifiedPageCount | union _LARGE_INTEGER OtherTransferCount | unsigned long DefaultHardErrorProcessing | struct _ETHREAD * ForkInProgress | struct _ETHREAD * RotateInProgress | struct _EX_PUSH_LOCK PageTableCommitmentLock | struct _EX_PUSH_LOCK AddressCreationLock | ||||||||||
0x036C | unsigned long Flags2 | long LastThreadExitStatus | |||||||||||||||
0x036C:0x00 | unsigned long JobNotReallyActive | ||||||||||||||||
0x036C:0x01 | unsigned long AccountingFolded | ||||||||||||||||
0x036C:0x02 | unsigned long NewProcessReported | ||||||||||||||||
0x036C:0x03 | unsigned long ExitProcessReported | ||||||||||||||||
0x036C:0x04 | unsigned long ReportCommitChanges | ||||||||||||||||
0x036C:0x05 | unsigned long LastReportMemory | ||||||||||||||||
0x036C:0x06 | unsigned long ReportPhysicalPageChanges | ||||||||||||||||
0x036C:0x07 | unsigned long HandleTableRundown | ||||||||||||||||
0x036C:0x08 | unsigned long NeedsHandleRundown | ||||||||||||||||
0x036C:0x09 | unsigned long RefTraceEnabled | ||||||||||||||||
0x036C:0x0A | unsigned long NumaAware | ||||||||||||||||
0x036C:0x0B | unsigned long ProtectedProcess | ||||||||||||||||
0x036C:0x0C | unsigned long DefaultPagePriority | ||||||||||||||||
0x036C:0x0F | unsigned long PrimaryTokenFrozen | ||||||||||||||||
0x036C:0x10 | unsigned long ProcessVerifierTarget | ||||||||||||||||
0x036C:0x11 | unsigned long StackRandomizationDisabled | ||||||||||||||||
0x036C:0x12 | unsigned long AffinityPermanent | ||||||||||||||||
0x036C:0x13 | unsigned long AffinityUpdateEnable | ||||||||||||||||
0x036C:0x14 | unsigned long CrossSessionCreate | ||||||||||||||||
0x036C:0x15 | unsigned long LowVaAccessible | ||||||||||||||||
0x0370 | unsigned long Flags | uint64_t CommitChargeLimit | struct _EX_FAST_REF PrefetchTrace | uint64_t HardwareTrigger | struct _ETHREAD * ForkInProgress | struct _ETHREAD * RotateInProgress | struct _EX_PUSH_LOCK PageTableCommitmentLock | ||||||||||
0x0370:0x00 | unsigned long CreateReported | ||||||||||||||||
0x0370:0x01 | unsigned long NoDebugInherit | ||||||||||||||||
0x0370:0x02 | unsigned long ProcessExiting | ||||||||||||||||
0x0370:0x03 | unsigned long ProcessDelete | ||||||||||||||||
0x0370:0x04 | unsigned long Wow64SplitPages | ||||||||||||||||
0x0370:0x05 | unsigned long VmDeleted | ||||||||||||||||
0x0370:0x06 | unsigned long OutswapEnabled | ||||||||||||||||
0x0370:0x07 | unsigned long Outswapped | ||||||||||||||||
0x0370:0x08 | unsigned long ForkFailed | ||||||||||||||||
0x0370:0x09 | unsigned long Wow64VaSpace4Gb | ||||||||||||||||
0x0370:0x0A | unsigned long AddressSpaceInitialized | ||||||||||||||||
0x0370:0x0C | unsigned long SetTimerResolution | ||||||||||||||||
0x0370:0x0D | unsigned long BreakOnTermination | ||||||||||||||||
0x0370:0x0E | unsigned long DeprioritizeViews | ||||||||||||||||
0x0370:0x0F | unsigned long WriteWatch | ||||||||||||||||
0x0370:0x10 | unsigned long ProcessInSession | ||||||||||||||||
0x0370:0x11 | unsigned long OverrideAddressSpace | ||||||||||||||||
0x0370:0x12 | unsigned long HasAddressSpace | ||||||||||||||||
0x0370:0x13 | unsigned long LaunchPrefetched | ||||||||||||||||
0x0370:0x14 | unsigned long InjectInpageErrors | ||||||||||||||||
0x0370:0x15 | unsigned long VmTopDown | ||||||||||||||||
0x0370:0x16 | unsigned long ImageNotifyDone | ||||||||||||||||
0x0370:0x17 | unsigned long PdeUpdateNeeded | ||||||||||||||||
0x0370:0x18 | unsigned long VdmAllowed | ||||||||||||||||
0x0370:0x19 | unsigned long SmapAllowed | ||||||||||||||||
0x0370:0x1A | unsigned long ProcessInserted | ||||||||||||||||
0x0370:0x1B | unsigned long DefaultIoPriority | ||||||||||||||||
0x0370:0x1E | unsigned long ProcessSelfDelete | ||||||||||||||||
0x0370:0x1F | unsigned long SpareProcessFlags | ||||||||||||||||
0x0374 | long ExitStatus | ||||||||||||||||
0x0378 | unsigned long[2] Spares | uint16_t Spare7 | volatile uint64_t CommitChargePeak | struct _MM_AVL_TABLE * LockedPagesList | struct _EJOB * volatile CommitChargeJob | struct _ETHREAD * ForkInProgress | struct _ETHREAD * RotateInProgress | ||||||||||
0x037A | uint8_t SubSystemMinorVersion | ||||||||||||||||
0x037A | uint16_t SubSystemVersion | ||||||||||||||||
0x037B | uint8_t SubSystemMajorVersion | ||||||||||||||||
0x037C | uint8_t PriorityClass | ||||||||||||||||
0x0380 | unsigned long ModifiedPageCount | struct _MM_AVL_TABLE VadRoot | void * AweInfo | union _LARGE_INTEGER ReadOperationCount | struct _MM_AVL_TABLE * CloneRoot | struct _RTL_AVL_TREE CloneRoot | struct _EJOB * volatile CommitChargeJob | struct _ETHREAD * ForkInProgress | |||||||||
0x0384 | unsigned long JobStatus | ||||||||||||||||
0x0388 | unsigned long Flags | struct _SE_AUDIT_PROCESS_CREATION_INFO SeAuditProcessCreationInfo | union _LARGE_INTEGER WriteOperationCount | volatile uint64_t NumberOfPrivatePages | struct _RTL_AVL_TREE CloneRoot | struct _EJOB * volatile CommitChargeJob | |||||||||||
0x0388:0x00 | unsigned long CreateReported | ||||||||||||||||
0x0388:0x01 | unsigned long NoDebugInherit | ||||||||||||||||
0x0388:0x02 | unsigned long ProcessExiting | ||||||||||||||||
0x0388:0x03 | unsigned long ProcessDelete | ||||||||||||||||
0x0388:0x04 | unsigned long Wow64SplitPages | ||||||||||||||||
0x0388:0x05 | unsigned long VmDeleted | ||||||||||||||||
0x0388:0x06 | unsigned long OutswapEnabled | ||||||||||||||||
0x0388:0x07 | unsigned long Outswapped | ||||||||||||||||
0x0388:0x08 | unsigned long ForkFailed | ||||||||||||||||
0x0388:0x09 | unsigned long Wow64VaSpace4Gb | ||||||||||||||||
0x0388:0x0A | unsigned long AddressSpaceInitialized | ||||||||||||||||
0x0388:0x0C | unsigned long SetTimerResolution | ||||||||||||||||
0x0388:0x0D | unsigned long BreakOnTermination | ||||||||||||||||
0x0388:0x0E | unsigned long SessionCreationUnderway | ||||||||||||||||
0x0388:0x0F | unsigned long WriteWatch | ||||||||||||||||
0x0388:0x10 | unsigned long ProcessInSession | ||||||||||||||||
0x0388:0x11 | unsigned long OverrideAddressSpace | ||||||||||||||||
0x0388:0x12 | unsigned long HasAddressSpace | ||||||||||||||||
0x0388:0x13 | unsigned long LaunchPrefetched | ||||||||||||||||
0x0388:0x14 | unsigned long InjectInpageErrors | ||||||||||||||||
0x0388:0x15 | unsigned long VmTopDown | ||||||||||||||||
0x0388:0x16 | unsigned long ImageNotifyDone | ||||||||||||||||
0x0388:0x17 | unsigned long PdeUpdateNeeded | ||||||||||||||||
0x0388:0x18 | unsigned long VdmAllowed | ||||||||||||||||
0x0388:0x19 | unsigned long SmapAllowed | ||||||||||||||||
0x0388:0x1A | unsigned long CreateFailed | ||||||||||||||||
0x0388:0x1B | unsigned long DefaultIoPriority | ||||||||||||||||
0x0388:0x1E | unsigned long Spare1 | ||||||||||||||||
0x0388:0x1F | unsigned long Spare2 | ||||||||||||||||
0x038C | long ExitStatus | ||||||||||||||||
0x0390 | uint16_t NextPageColor | struct _MMSUPPORT Vm | union _LARGE_INTEGER OtherOperationCount | volatile uint64_t NumberOfLockedPages | volatile uint64_t NumberOfPrivatePages | struct _RTL_AVL_TREE CloneRoot | |||||||||||
0x0392 | uint8_t SubSystemMinorVersion | ||||||||||||||||
0x0392 | uint16_t SubSystemVersion | ||||||||||||||||
0x0393 | uint8_t SubSystemMajorVersion | ||||||||||||||||
0x0394 | uint8_t PriorityClass | ||||||||||||||||
0x0398 | struct _MM_AVL_TABLE VadRoot | union _LARGE_INTEGER ReadTransferCount | void * Win32Process | volatile uint64_t NumberOfLockedPages | volatile uint64_t NumberOfPrivatePages | ||||||||||||
0x03A0 | union _LARGE_INTEGER WriteTransferCount | struct _EJOB * volatile Job | void * Win32Process | volatile uint64_t NumberOfLockedPages | |||||||||||||
0x03A8 | union _LARGE_INTEGER OtherTransferCount | void * SectionObject | struct _EJOB * volatile Job | void * Win32Process | |||||||||||||
0x03B0 | uint64_t CommitChargeLimit | void * SectionBaseAddress | void * SectionObject | struct _EJOB * volatile Job | |||||||||||||
0x03B8 | volatile uint64_t CommitCharge | unsigned long Cookie | void * SectionBaseAddress | void * SectionObject | |||||||||||||
0x03C0 | unsigned long Cookie | volatile uint64_t CommitChargePeak | struct _PAGEFAULT_HISTORY * WorkingSetWatch | unsigned long Cookie | void * SectionBaseAddress | ||||||||||||
0x03C8 | struct _ALPC_PROCESS_CONTEXT AlpcContext | struct _MMSUPPORT Vm | void * Win32WindowStation | struct _PAGEFAULT_HISTORY * WorkingSetWatch | unsigned long Cookie | ||||||||||||
0x03D0 | void * InheritedFromUniqueProcessId | void * Win32WindowStation | struct _PAGEFAULT_HISTORY * WorkingSetWatch | ||||||||||||||
0x03D8 | unsigned long Cookie | void * LdtInformation | void * InheritedFromUniqueProcessId | void * Win32WindowStation | |||||||||||||
0x03E0 | struct _EPROCESS * CreatorProcess | volatile uint64_t OwnerProcessId | void * LdtInformation | void * InheritedFromUniqueProcessId | |||||||||||||
0x03E0 | uint64_t ConsoleHostProcess | ||||||||||||||||
0x03E8 | struct _PEB * Peb | volatile uint64_t OwnerProcessId | void * LdtInformation | ||||||||||||||
0x03F0 | void * Session | struct _PEB * Peb | volatile uint64_t OwnerProcessId | ||||||||||||||
0x03F8 | void * AweInfo | void * Session | struct _PEB * Peb | ||||||||||||||
0x0400 | struct _EPROCESS_QUOTA_BLOCK * QuotaBlock | void * AweInfo | void * Session | ||||||||||||||
0x0408 | struct _HANDLE_TABLE * ObjectTable | struct _EPROCESS_QUOTA_BLOCK * QuotaBlock | void * AweInfo | ||||||||||||||
0x0410 | void * DebugPort | struct _HANDLE_TABLE * ObjectTable | struct _EPROCESS_QUOTA_BLOCK * QuotaBlock | ||||||||||||||
0x0418 | struct _LIST_ENTRY MmProcessLinks | void * Wow64Process | void * DebugPort | struct _HANDLE_TABLE * ObjectTable | |||||||||||||
0x0420 | void * DeviceMap | void * Wow64Process | void * DebugPort | ||||||||||||||
0x0428 | void * HighestUserAddress | void * EtwDataSource | void * DeviceMap | void * Wow64Process | struct _EWOW64PROCESS * WoW64Process | ||||||||||||
0x0430 | unsigned long ModifiedPageCount | uint64_t PageDirectoryPte | void * EtwDataSource | void * DeviceMap | |||||||||||||
0x0434 | unsigned long Flags2 | ||||||||||||||||
0x0434:0x00 | unsigned long JobNotReallyActive | ||||||||||||||||
0x0434:0x01 | unsigned long AccountingFolded | ||||||||||||||||
0x0434:0x02 | unsigned long NewProcessReported | ||||||||||||||||
0x0434:0x03 | unsigned long ExitProcessReported | ||||||||||||||||
0x0434:0x04 | unsigned long ReportCommitChanges | ||||||||||||||||
0x0434:0x05 | unsigned long LastReportMemory | ||||||||||||||||
0x0434:0x06 | unsigned long ReportPhysicalPageChanges | ||||||||||||||||
0x0434:0x07 | unsigned long HandleTableRundown | ||||||||||||||||
0x0434:0x08 | unsigned long NeedsHandleRundown | ||||||||||||||||
0x0434:0x09 | unsigned long RefTraceEnabled | ||||||||||||||||
0x0434:0x0A | unsigned long NumaAware | ||||||||||||||||
0x0434:0x0B | unsigned long ProtectedProcess | ||||||||||||||||
0x0434:0x0C | unsigned long DefaultPagePriority | ||||||||||||||||
0x0434:0x0F | unsigned long PrimaryTokenFrozen | ||||||||||||||||
0x0434:0x10 | unsigned long ProcessVerifierTarget | ||||||||||||||||
0x0434:0x11 | unsigned long StackRandomizationDisabled | ||||||||||||||||
0x0434:0x12 | unsigned long AffinityPermanent | ||||||||||||||||
0x0434:0x13 | unsigned long AffinityUpdateEnable | ||||||||||||||||
0x0434:0x14 | unsigned long PropagateNode | ||||||||||||||||
0x0434:0x15 | unsigned long ExplicitAffinity | ||||||||||||||||
0x0434:0x16 | unsigned long Spare1 | ||||||||||||||||
0x0434:0x17 | unsigned long ForceRelocateImages | ||||||||||||||||
0x0434:0x18 | unsigned long DisallowStrippedImages | ||||||||||||||||
0x0434:0x19 | unsigned long LowVaAccessible | ||||||||||||||||
0x0438 | unsigned long Flags | uint8_t[15] ImageFileName | uint64_t PageDirectoryPte | void * EtwDataSource | |||||||||||||
0x0438:0x00 | unsigned long CreateReported | ||||||||||||||||
0x0438:0x01 | unsigned long NoDebugInherit | ||||||||||||||||
0x0438:0x02 | unsigned long ProcessExiting | ||||||||||||||||
0x0438:0x03 | unsigned long ProcessDelete | ||||||||||||||||
0x0438:0x04 | unsigned long Wow64SplitPages | ||||||||||||||||
0x0438:0x05 | unsigned long VmDeleted | ||||||||||||||||
0x0438:0x06 | unsigned long OutswapEnabled | ||||||||||||||||
0x0438:0x07 | unsigned long Outswapped | ||||||||||||||||
0x0438:0x08 | unsigned long ForkFailed | ||||||||||||||||
0x0438:0x09 | unsigned long Wow64VaSpace4Gb | ||||||||||||||||
0x0438:0x0A | unsigned long AddressSpaceInitialized | ||||||||||||||||
0x0438:0x0C | unsigned long SetTimerResolution | ||||||||||||||||
0x0438:0x0D | unsigned long BreakOnTermination | ||||||||||||||||
0x0438:0x0E | unsigned long DeprioritizeViews | ||||||||||||||||
0x0438:0x0F | unsigned long WriteWatch | ||||||||||||||||
0x0438:0x10 | unsigned long ProcessInSession | ||||||||||||||||
0x0438:0x11 | unsigned long OverrideAddressSpace | ||||||||||||||||
0x0438:0x12 | unsigned long HasAddressSpace | ||||||||||||||||
0x0438:0x13 | unsigned long LaunchPrefetched | ||||||||||||||||
0x0438:0x14 | unsigned long InjectInpageErrors | ||||||||||||||||
0x0438:0x15 | unsigned long VmTopDown | ||||||||||||||||
0x0438:0x16 | unsigned long ImageNotifyDone | ||||||||||||||||
0x0438:0x17 | unsigned long PdeUpdateNeeded | ||||||||||||||||
0x0438:0x18 | unsigned long VdmAllowed | ||||||||||||||||
0x0438:0x19 | unsigned long CrossSessionCreate | ||||||||||||||||
0x0438:0x1A | unsigned long ProcessInserted | ||||||||||||||||
0x0438:0x1B | unsigned long DefaultIoPriority | ||||||||||||||||
0x0438:0x1E | unsigned long ProcessSelfDelete | ||||||||||||||||
0x0438:0x1F | unsigned long SetTimerResolutionLink | ||||||||||||||||
0x043C | long ExitStatus | ||||||||||||||||
0x0440 | struct _MM_AVL_TABLE VadRoot | uint8_t[15] ImageFileName | uint64_t PageDirectoryPte | ||||||||||||||
0x0447 | uint8_t PriorityClass | ||||||||||||||||
0x0448 | void * SecurityPort | uint8_t[15] ImageFileName | struct _FILE_OBJECT * ImageFilePointer | ||||||||||||||
0x044F | uint8_t PriorityClass | ||||||||||||||||
0x0450 | struct _LIST_ENTRY MmProcessLinks | struct _SE_AUDIT_PROCESS_CREATION_INFO SeAuditProcessCreationInfo | void * SecurityPort | uint8_t[15] ImageFileName | |||||||||||||
0x0457 | uint8_t PriorityClass | ||||||||||||||||
0x0458 | struct _LIST_ENTRY JobLinks | struct _SE_AUDIT_PROCESS_CREATION_INFO SeAuditProcessCreationInfo | void * SecurityPort | ||||||||||||||
0x045F | uint8_t PriorityClass | ||||||||||||||||
0x0460 | unsigned long ModifiedPageCount | struct _LIST_ENTRY JobLinks | struct _SE_AUDIT_PROCESS_CREATION_INFO SeAuditProcessCreationInfo | void * SecurityPort | |||||||||||||
0x0464 | unsigned long Flags2 | ||||||||||||||||
0x0464:0x00 | unsigned long JobNotReallyActive | ||||||||||||||||
0x0464:0x01 | unsigned long AccountingFolded | ||||||||||||||||
0x0464:0x02 | unsigned long NewProcessReported | ||||||||||||||||
0x0464:0x03 | unsigned long ExitProcessReported | ||||||||||||||||
0x0464:0x04 | unsigned long ReportCommitChanges | ||||||||||||||||
0x0464:0x05 | unsigned long LastReportMemory | ||||||||||||||||
0x0464:0x06 | unsigned long Spare1 | ||||||||||||||||
0x0464:0x07 | unsigned long HandleTableRundown | ||||||||||||||||
0x0464:0x08 | unsigned long NeedsHandleRundown | ||||||||||||||||
0x0464:0x09 | unsigned long RefTraceEnabled | ||||||||||||||||
0x0464:0x0A | unsigned long NumaAware | ||||||||||||||||
0x0464:0x0B | unsigned long Spare2 | ||||||||||||||||
0x0464:0x0C | unsigned long DefaultPagePriority | ||||||||||||||||
0x0464:0x0F | unsigned long PrimaryTokenFrozen | ||||||||||||||||
0x0464:0x10 | unsigned long ProcessVerifierTarget | ||||||||||||||||
0x0464:0x11 | unsigned long StackRandomizationDisabled | ||||||||||||||||
0x0464:0x12 | unsigned long AffinityPermanent | ||||||||||||||||
0x0464:0x13 | unsigned long AffinityUpdateEnable | ||||||||||||||||
0x0464:0x14 | unsigned long PropagateNode | ||||||||||||||||
0x0464:0x15 | unsigned long ExplicitAffinity | ||||||||||||||||
0x0464:0x16 | unsigned long LowVaAccessible | ||||||||||||||||
0x0464:0x17 | unsigned long ForceRelocateImages | ||||||||||||||||
0x0464:0x18 | unsigned long DisallowStrippedImages | ||||||||||||||||
0x0464:0x19 | unsigned long HighEntropyASLREnabled | ||||||||||||||||
0x0464:0x1A | unsigned long ForceStackCheck | ||||||||||||||||
0x0464:0x1B | unsigned long ProcessDeepFrozen | ||||||||||||||||
0x0464:0x1C | unsigned long ProcessDeepFreezeRequest | ||||||||||||||||
0x0464:0x1D | unsigned long ProcessDeepFreezeInProgress | ||||||||||||||||
0x0464:0x1E | unsigned long DisallowWin32kSystemCalls | ||||||||||||||||
0x0464:0x1F | unsigned long SpareBits | ||||||||||||||||
0x0468 | unsigned long Flags | void * HighestUserAddress | struct _LIST_ENTRY JobLinks | struct _SE_AUDIT_PROCESS_CREATION_INFO SeAuditProcessCreationInfo | |||||||||||||
0x0468:0x00 | unsigned long CreateReported | ||||||||||||||||
0x0468:0x01 | unsigned long NoDebugInherit | ||||||||||||||||
0x0468:0x02 | unsigned long ProcessExiting | ||||||||||||||||
0x0468:0x03 | unsigned long ProcessDelete | ||||||||||||||||
0x0468:0x04 | unsigned long Wow64SplitPages | ||||||||||||||||
0x0468:0x05 | unsigned long VmDeleted | ||||||||||||||||
0x0468:0x06 | unsigned long OutswapEnabled | ||||||||||||||||
0x0468:0x07 | unsigned long Outswapped | ||||||||||||||||
0x0468:0x08 | unsigned long ForkFailed | ||||||||||||||||
0x0468:0x09 | unsigned long Wow64VaSpace4Gb | ||||||||||||||||
0x0468:0x0A | unsigned long AddressSpaceInitialized | ||||||||||||||||
0x0468:0x0C | unsigned long SetTimerResolution | ||||||||||||||||
0x0468:0x0D | unsigned long BreakOnTermination | ||||||||||||||||
0x0468:0x0E | unsigned long DeprioritizeViews | ||||||||||||||||
0x0468:0x0F | unsigned long WriteWatch | ||||||||||||||||
0x0468:0x10 | unsigned long ProcessInSession | ||||||||||||||||
0x0468:0x11 | unsigned long OverrideAddressSpace | ||||||||||||||||
0x0468:0x12 | unsigned long HasAddressSpace | ||||||||||||||||
0x0468:0x13 | unsigned long LaunchPrefetched | ||||||||||||||||
0x0468:0x14 | unsigned long InjectInpageErrors | ||||||||||||||||
0x0468:0x15 | unsigned long VmTopDown | ||||||||||||||||
0x0468:0x16 | unsigned long ImageNotifyDone | ||||||||||||||||
0x0468:0x17 | unsigned long PdeUpdateNeeded | ||||||||||||||||
0x0468:0x18 | unsigned long VdmAllowed | ||||||||||||||||
0x0468:0x19 | unsigned long CrossSessionCreate | ||||||||||||||||
0x0468:0x1A | unsigned long ProcessInserted | ||||||||||||||||
0x0468:0x1B | unsigned long DefaultIoPriority | ||||||||||||||||
0x0468:0x1E | unsigned long ProcessSelfDelete | ||||||||||||||||
0x0468:0x1F | unsigned long SetTimerResolutionLink | ||||||||||||||||
0x046C | long ExitStatus | ||||||||||||||||
0x0470 | struct _MM_AVL_TABLE VadRoot | struct _LIST_ENTRY ThreadListHead | void * HighestUserAddress | struct _LIST_ENTRY JobLinks | |||||||||||||
0x0478 | struct _LIST_ENTRY ThreadListHead | void * HighestUserAddress | |||||||||||||||
0x0480 | struct _ALPC_PROCESS_CONTEXT AlpcContext | volatile unsigned long ActiveThreads | struct _LIST_ENTRY ThreadListHead | void * HighestUserAddress | |||||||||||||
0x0484 | unsigned long ImagePathHash | ||||||||||||||||
0x0488 | unsigned long DefaultHardErrorProcessing | volatile unsigned long ActiveThreads | struct _LIST_ENTRY ThreadListHead | ||||||||||||||
0x048C | long LastThreadExitStatus | unsigned long ImagePathHash | |||||||||||||||
0x0490 | struct _EX_FAST_REF PrefetchTrace | unsigned long DefaultHardErrorProcessing | volatile unsigned long ActiveThreads | ||||||||||||||
0x0494 | long LastThreadExitStatus | unsigned long ImagePathHash | |||||||||||||||
0x0498 | struct _MM_AVL_TABLE * LockedPagesList | void * LockedPagesList | struct _EX_FAST_REF PrefetchTrace | unsigned long DefaultHardErrorProcessing | volatile unsigned long ActiveThreads | ||||||||||||
0x049C | long LastThreadExitStatus | unsigned long ImagePathHash | |||||||||||||||
0x04A0 | struct _LIST_ENTRY TimerResolutionLink | volatile uint64_t VadPhysicalPages | union _LARGE_INTEGER ReadOperationCount | void * LockedPagesList | struct _EX_FAST_REF PrefetchTrace | unsigned long DefaultHardErrorProcessing | |||||||||||
0x04A4 | long LastThreadExitStatus | ||||||||||||||||
0x04A8 | uint64_t VadPhysicalPagesLimit | union _LARGE_INTEGER WriteOperationCount | union _LARGE_INTEGER ReadOperationCount | void * LockedPagesList | struct _EX_FAST_REF PrefetchTrace | ||||||||||||
0x04B0 | unsigned long RequestedTimerResolution | struct _ALPC_PROCESS_CONTEXT AlpcContext | union _LARGE_INTEGER OtherOperationCount | union _LARGE_INTEGER WriteOperationCount | union _LARGE_INTEGER ReadOperationCount | void * LockedPagesList | |||||||||||
0x04B4 | unsigned long ActiveThreadsHighWatermark | ||||||||||||||||
0x04B8 | unsigned long SmallestTimerResolution | union _LARGE_INTEGER ReadTransferCount | union _LARGE_INTEGER OtherOperationCount | union _LARGE_INTEGER WriteOperationCount | union _LARGE_INTEGER ReadOperationCount | ||||||||||||
0x04C0 | struct _PO_DIAG_STACK_RECORD * TimerResolutionStackRecord | union _LARGE_INTEGER WriteTransferCount | union _LARGE_INTEGER ReadTransferCount | union _LARGE_INTEGER OtherOperationCount | union _LARGE_INTEGER WriteOperationCount | ||||||||||||
0x04C8 | uint64_t SequenceNumber | union _LARGE_INTEGER OtherTransferCount | union _LARGE_INTEGER WriteTransferCount | union _LARGE_INTEGER ReadTransferCount | union _LARGE_INTEGER OtherOperationCount | ||||||||||||
0x04D0 | uint64_t CreateInterruptTime | struct _LIST_ENTRY TimerResolutionLink | uint64_t CommitChargeLimit | volatile uint64_t CommitCharge | union _LARGE_INTEGER OtherTransferCount | union _LARGE_INTEGER WriteTransferCount | union _LARGE_INTEGER ReadTransferCount | ||||||||||
0x04D8 | uint64_t CreateUnbiasedInterruptTime | volatile uint64_t CommitCharge | struct _MMSUPPORT Vm | uint64_t CommitChargeLimit | union _LARGE_INTEGER OtherTransferCount | union _LARGE_INTEGER WriteTransferCount | |||||||||||
0x04E0 | struct _PO_DIAG_STACK_RECORD * TimerResolutionStackRecord | volatile uint64_t CommitChargePeak | volatile uint64_t CommitCharge | uint64_t CommitChargeLimit | union _LARGE_INTEGER OtherTransferCount | ||||||||||||
0x04E8 | unsigned long RequestedTimerResolution | struct _MMSUPPORT Vm | struct _MMSUPPORT Vm | volatile uint64_t CommitChargePeak | volatile uint64_t CommitCharge | uint64_t CommitChargeLimit | |||||||||||
0x04EC | unsigned long SmallestTimerResolution | ||||||||||||||||
0x04F0 | union _LARGE_INTEGER ExitTime | struct _MMSUPPORT Vm | volatile uint64_t CommitChargePeak | volatile uint64_t CommitCharge | |||||||||||||
0x04F8 | struct _INVERTED_FUNCTION_TABLE * InvertedFunctionTable | struct _MMSUPPORT Vm | volatile uint64_t CommitChargePeak | ||||||||||||||
0x0500 | struct _EX_PUSH_LOCK InvertedFunctionTableLock | struct _MMSUPPORT Vm | |||||||||||||||
0x0508 | unsigned long ActiveThreadsHighWatermark | ||||||||||||||||
0x050C | unsigned long LargePrivateVadCount | ||||||||||||||||
0x0510 | void * WnfContext | ||||||||||||||||
0x0518 | enum _SE_SIGNING_LEVEL SignatureLevel | ||||||||||||||||
0x051C | unsigned long KeepAliveCounter | ||||||||||||||||
0x0520 | struct _PROCESS_DISK_COUNTERS * DiskCounters | ||||||||||||||||
0x0578 | struct _LIST_ENTRY MmProcessLinks | ||||||||||||||||
0x0588 | unsigned long ModifiedPageCount | ||||||||||||||||
0x058C | long ExitStatus | ||||||||||||||||
0x0590 | struct _MM_AVL_TABLE VadRoot | ||||||||||||||||
0x05C0 | volatile uint64_t VadPhysicalPages | struct _LIST_ENTRY MmProcessLinks | |||||||||||||||
0x05C8 | uint64_t VadPhysicalPagesLimit | ||||||||||||||||
0x05D0 | struct _ALPC_PROCESS_CONTEXT AlpcContext | unsigned long ModifiedPageCount | |||||||||||||||
0x05D4 | long ExitStatus | ||||||||||||||||
0x05D8 | struct _RTL_AVL_TREE VadRoot | struct _LIST_ENTRY MmProcessLinks | |||||||||||||||
0x05E0 | void * VadHint | ||||||||||||||||
0x05E8 | uint64_t VadCount | unsigned long ModifiedPageCount | |||||||||||||||
0x05EC | long ExitStatus | ||||||||||||||||
0x05F0 | struct _LIST_ENTRY TimerResolutionLink | volatile uint64_t VadPhysicalPages | struct _RTL_AVL_TREE VadRoot | struct _LIST_ENTRY MmProcessLinks | |||||||||||||
0x05F8 | uint64_t VadPhysicalPagesLimit | void * VadHint | struct _LIST_ENTRY MmProcessLinks | ||||||||||||||
0x0600 | struct _PO_DIAG_STACK_RECORD * TimerResolutionStackRecord | struct _ALPC_PROCESS_CONTEXT AlpcContext | uint64_t VadCount | unsigned long ModifiedPageCount | |||||||||||||
0x0604 | long ExitStatus | ||||||||||||||||
0x0608 | unsigned long RequestedTimerResolution | volatile uint64_t VadPhysicalPages | struct _RTL_AVL_TREE VadRoot | unsigned long ModifiedPageCount | |||||||||||||
0x060C | unsigned long SmallestTimerResolution | long ExitStatus | |||||||||||||||
0x0610 | union _LARGE_INTEGER ExitTime | uint64_t VadPhysicalPagesLimit | void * VadHint | struct _RTL_AVL_TREE VadRoot | |||||||||||||
0x0618 | struct _INVERTED_FUNCTION_TABLE * InvertedFunctionTable | struct _ALPC_PROCESS_CONTEXT AlpcContext | uint64_t VadCount | void * VadHint | |||||||||||||
0x0620 | struct _EX_PUSH_LOCK InvertedFunctionTableLock | struct _LIST_ENTRY TimerResolutionLink | volatile uint64_t VadPhysicalPages | uint64_t VadCount | |||||||||||||
0x0628 | unsigned long ActiveThreadsHighWatermark | uint64_t VadPhysicalPagesLimit | volatile uint64_t VadPhysicalPages | ||||||||||||||
0x062C | unsigned long LargePrivateVadCount | ||||||||||||||||
0x0630 | struct _EX_PUSH_LOCK ThreadListLock | struct _PO_DIAG_STACK_RECORD * TimerResolutionStackRecord | struct _ALPC_PROCESS_CONTEXT AlpcContext | uint64_t VadPhysicalPagesLimit | |||||||||||||
0x0638 | void * WnfContext | unsigned long RequestedTimerResolution | struct _LIST_ENTRY TimerResolutionLink | struct _ALPC_PROCESS_CONTEXT AlpcContext | |||||||||||||
0x063C | unsigned long SmallestTimerResolution | ||||||||||||||||
0x0640 | uint64_t SectionMappingSize | union _LARGE_INTEGER ExitTime | |||||||||||||||
0x0648 | uint8_t SignatureLevel | struct _INVERTED_FUNCTION_TABLE * InvertedFunctionTable | struct _PO_DIAG_STACK_RECORD * TimerResolutionStackRecord | ||||||||||||||
0x0649 | uint8_t SectionSignatureLevel | ||||||||||||||||
0x064A | uint8_t[2] SpareByte20 | ||||||||||||||||
0x064C | unsigned long KeepAliveCounter | ||||||||||||||||
0x0650 | struct _PROCESS_DISK_COUNTERS * DiskCounters | struct _EX_PUSH_LOCK InvertedFunctionTableLock | unsigned long RequestedTimerResolution | struct _LIST_ENTRY TimerResolutionLink | |||||||||||||
0x0654 | unsigned long SmallestTimerResolution | ||||||||||||||||
0x0658 | uint64_t LastFreezeInterruptTime | unsigned long ActiveThreadsHighWatermark | union _LARGE_INTEGER ExitTime | struct _LIST_ENTRY TimerResolutionLink | |||||||||||||
0x065C | unsigned long LargePrivateVadCount | ||||||||||||||||
0x0660 | struct _EX_PUSH_LOCK ThreadListLock | struct _INVERTED_FUNCTION_TABLE * InvertedFunctionTable | struct _PO_DIAG_STACK_RECORD * TimerResolutionStackRecord | ||||||||||||||
0x0668 | void * WnfContext | struct _EX_PUSH_LOCK InvertedFunctionTableLock | unsigned long RequestedTimerResolution | struct _PO_DIAG_STACK_RECORD * TimerResolutionStackRecord | |||||||||||||
0x066C | unsigned long SmallestTimerResolution | ||||||||||||||||
0x0670 | uint64_t Spare0 | unsigned long ActiveThreadsHighWatermark | union _LARGE_INTEGER ExitTime | unsigned long RequestedTimerResolution | |||||||||||||
0x0674 | unsigned long LargePrivateVadCount | unsigned long SmallestTimerResolution | |||||||||||||||
0x0678 | uint8_t SignatureLevel | struct _EX_PUSH_LOCK ThreadListLock | struct _INVERTED_FUNCTION_TABLE * InvertedFunctionTable | union _LARGE_INTEGER ExitTime | |||||||||||||
0x0679 | uint8_t SectionSignatureLevel | ||||||||||||||||
0x067A | struct _PS_PROTECTION Protection | ||||||||||||||||
0x067B | uint8_t[1] SpareByte20 | ||||||||||||||||
0x067C | unsigned long Flags3 | ||||||||||||||||
0x067C:0x00 | unsigned long Minimal | ||||||||||||||||
0x0680 | long SvmReserved | void * WnfContext | struct _EX_PUSH_LOCK InvertedFunctionTableLock | struct _INVERTED_FUNCTION_TABLE * InvertedFunctionTable | |||||||||||||
0x0688 | void * SvmReserved1 | uint64_t Spare0 | unsigned long ActiveThreadsHighWatermark | struct _EX_PUSH_LOCK InvertedFunctionTableLock | |||||||||||||
0x068C | unsigned long LargePrivateVadCount | ||||||||||||||||
0x0690 | uint64_t SvmReserved2 | uint8_t SignatureLevel | struct _EX_PUSH_LOCK ThreadListLock | unsigned long ActiveThreadsHighWatermark | |||||||||||||
0x0691 | uint8_t SectionSignatureLevel | ||||||||||||||||
0x0692 | struct _PS_PROTECTION Protection | ||||||||||||||||
0x0693 | uint8_t[1] SpareByte20 | ||||||||||||||||
0x0694 | unsigned long Flags3 | unsigned long LargePrivateVadCount | |||||||||||||||
0x0694:0x00 | unsigned long Minimal | ||||||||||||||||
0x0694:0x01 | unsigned long ReplacingPageRoot | ||||||||||||||||
0x0698 | uint64_t LastFreezeInterruptTime | long SvmReserved | void * WnfContext | struct _EX_PUSH_LOCK ThreadListLock | |||||||||||||
0x06A0 | struct _PROCESS_DISK_COUNTERS * DiskCounters | void * SvmReserved1 | uint64_t Spare0 | void * WnfContext | |||||||||||||
0x06A8 | void * PicoContext | uint64_t SvmReserved2 | uint8_t SignatureLevel | uint64_t Spare0 | |||||||||||||
0x06A9 | uint8_t SectionSignatureLevel | ||||||||||||||||
0x06AA | struct _PS_PROTECTION Protection | ||||||||||||||||
0x06AB | uint8_t HangCount | ||||||||||||||||
0x06AC | unsigned long Flags3 | ||||||||||||||||
0x06AC:0x00 | unsigned long Minimal | ||||||||||||||||
0x06AC:0x01 | unsigned long ReplacingPageRoot | ||||||||||||||||
0x06AC:0x02 | unsigned long DisableNonSystemFonts | ||||||||||||||||
0x06AC:0x03 | unsigned long AuditNonSystemFontLoading | ||||||||||||||||
0x06AC:0x04 | unsigned long Crashed | ||||||||||||||||
0x06AC:0x05 | unsigned long JobVadsAreTracked | ||||||||||||||||
0x06AC:0x06 | unsigned long VadTrackingDisabled | ||||||||||||||||
0x06AC:0x07 | unsigned long AuxiliaryProcess | ||||||||||||||||
0x06AC:0x08 | unsigned long SubsystemProcess | ||||||||||||||||
0x06AC:0x09 | unsigned long IndirectCpuSets | ||||||||||||||||
0x06AC:0x0A | unsigned long InPrivate | ||||||||||||||||
0x06B0 | unsigned long KeepAliveCounter | uint64_t LastFreezeInterruptTime | long DeviceAsid | uint8_t SignatureLevel | |||||||||||||
0x06B1 | uint8_t SectionSignatureLevel | ||||||||||||||||
0x06B2 | struct _PS_PROTECTION Protection | ||||||||||||||||
0x06B3 | uint8_t HangCount | ||||||||||||||||
0x06B4 | unsigned long NoWakeKeepAliveCounter | unsigned long Flags3 | |||||||||||||||
0x06B4:0x00 | unsigned long Minimal | ||||||||||||||||
0x06B4:0x01 | unsigned long ReplacingPageRoot | ||||||||||||||||
0x06B4:0x02 | unsigned long DisableNonSystemFonts | ||||||||||||||||
0x06B4:0x03 | unsigned long AuditNonSystemFontLoading | ||||||||||||||||
0x06B4:0x04 | unsigned long Crashed | ||||||||||||||||
0x06B4:0x05 | unsigned long JobVadsAreTracked | ||||||||||||||||
0x06B4:0x06 | unsigned long VadTrackingDisabled | ||||||||||||||||
0x06B4:0x07 | unsigned long AuxiliaryProcess | ||||||||||||||||
0x06B4:0x08 | unsigned long SubsystemProcess | ||||||||||||||||
0x06B4:0x09 | unsigned long IndirectCpuSets | ||||||||||||||||
0x06B4:0x0A | unsigned long InPrivate | ||||||||||||||||
0x06B4:0x0B | unsigned long ProhibitRemoteImageMap | ||||||||||||||||
0x06B4:0x0C | unsigned long ProhibitLowILImageMap | ||||||||||||||||
0x06B4:0x0D | unsigned long SignatureMitigationOptIn | ||||||||||||||||
0x06B8 | uint64_t DeepFreezeStartTime | struct _PROCESS_DISK_COUNTERS * DiskCounters | void * SvmData | long DeviceAsid | |||||||||||||
0x06C0 | uint64_t CommitChargeLimit | void * PicoContext | struct _EX_PUSH_LOCK SvmProcessLock | void * SvmData | |||||||||||||
0x06C8 | volatile uint64_t CommitChargePeak | uint64_t SecretIdentity | uint64_t SvmLock | struct _EX_PUSH_LOCK SvmProcessLock | |||||||||||||
0x06D0 | unsigned long HighPriorityFaultsAllowed | uint64_t SecurePid | struct _LIST_ENTRY SvmProcessDeviceListHead | uint64_t SvmLock | |||||||||||||
0x06D8 | uint64_t SequenceNumber | void * ContextBuffer | struct _LIST_ENTRY SvmProcessDeviceListHead | ||||||||||||||
0x06E0 | uint64_t CreateInterruptTime | unsigned long KeepAliveCounter | uint64_t LastFreezeInterruptTime | ||||||||||||||
0x06E4 | unsigned long NoWakeKeepAliveCounter | ||||||||||||||||
0x06E8 | uint64_t CreateUnbiasedInterruptTime | unsigned long HighPriorityFaultsAllowed | struct _PROCESS_DISK_COUNTERS * DiskCounters | uint64_t LastFreezeInterruptTime | |||||||||||||
0x06F0 | struct _PROCESS_ENERGY_VALUES * EnergyValues | void * PicoContext | struct _PROCESS_DISK_COUNTERS * DiskCounters | ||||||||||||||
0x06F8 | void * VmContext | uint64_t TrustletIdentity | void * PicoContext | ||||||||||||||
0x0700 | unsigned long KeepAliveCounter | uint64_t TrustletIdentity | |||||||||||||||
0x0704 | unsigned long NoWakeKeepAliveCounter | ||||||||||||||||
0x0708 | unsigned long HighPriorityFaultsAllowed | unsigned long KeepAliveCounter | |||||||||||||||
0x070C | unsigned long NoWakeKeepAliveCounter | ||||||||||||||||
0x0710 | struct _PROCESS_ENERGY_VALUES * EnergyValues | unsigned long HighPriorityFaultsAllowed | |||||||||||||||
0x0718 | void * VmContext | struct _PROCESS_ENERGY_VALUES * EnergyValues | |||||||||||||||
0x0720 | uint64_t SequenceNumber | struct _ESILO * Silo | void * VmContext | ||||||||||||||
0x0728 | uint64_t CreateInterruptTime | struct _LIST_ENTRY SiloEntry | uint64_t SequenceNumber | ||||||||||||||
0x0730 | uint64_t CreateUnbiasedInterruptTime | uint64_t CreateInterruptTime | |||||||||||||||
0x0738 | uint64_t TotalUnbiasedFrozenTime | uint64_t SequenceNumber | uint64_t CreateUnbiasedInterruptTime | ||||||||||||||
0x0740 | uint64_t LastAppStateUpdateTime | uint64_t CreateInterruptTime | uint64_t TotalUnbiasedFrozenTime | ||||||||||||||
0x0748:0x00 | uint64_t LastAppStateUptime | uint64_t CreateUnbiasedInterruptTime | uint64_t LastAppStateUpdateTime | ||||||||||||||
0x0748:0x3D | uint64_t LastAppState | ||||||||||||||||
0x0750 | volatile uint64_t SharedCommitCharge | uint64_t TotalUnbiasedFrozenTime | uint64_t LastAppStateUptime | ||||||||||||||
0x0750:0x3D | uint64_t LastAppState | ||||||||||||||||
0x0758 | struct _EX_PUSH_LOCK SharedCommitLock | uint64_t LastAppStateUpdateTime | volatile uint64_t SharedCommitCharge | ||||||||||||||
0x0760 | struct _LIST_ENTRY SharedCommitLinks | uint64_t LastAppStateUptime | struct _EX_PUSH_LOCK SharedCommitLock | ||||||||||||||
0x0760:0x3D | uint64_t LastAppState | ||||||||||||||||
0x0768 | volatile uint64_t SharedCommitCharge | struct _LIST_ENTRY SharedCommitLinks | |||||||||||||||
0x0770 | struct _EX_PUSH_LOCK SharedCommitLock | ||||||||||||||||
0x0778 | struct _LIST_ENTRY SharedCommitLinks | uint64_t AllowedCpuSets | |||||||||||||||
0x0778 | uint64_t * AllowedCpuSetsIndirect | ||||||||||||||||
0x0780 | uint64_t DefaultCpuSets | ||||||||||||||||
0x0780 | uint64_t * DefaultCpuSetsIndirect | ||||||||||||||||
0x0788 | uint64_t AllowedCpuSets | ||||||||||||||||
0x0788 | uint64_t * AllowedCpuSetsIndirect | ||||||||||||||||
0x0790 | uint64_t DefaultCpuSets | ||||||||||||||||
0x0790 | uint64_t * DefaultCpuSetsIndirect |