Min version | XP | XP SP3 | 2003/XP64 | 2003/XP64 SP1 | 2003/XP64 SP2 | 2003/XP64 SP2 | 2003/XP64 SP2 | Vista | Vista SP1 | Vista SP1 | Vista SP2 | 7 | 7 | 7 SP1 | 8 Pre RTM | 8 Pre RTM | 8 | 8.1 | 8.1 Update 1 | 8.1 Update 1 | 10 Pre RTM | 10 Pre RTM | 10 Pre RTM | 10 Pre RTM | 10 | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Max version | XP SP3 | Vista SP2 | 8 | 10 TH2 | ||||||||||||||||||||||||||||||||
Architecture | x86 | x86 | x86 | x86 | x64 | x86 | x64 | x86 | x64 | x86 | x86 | x86 | x86 | x64 | x86 | x64 | x86 | x64 | x86 | x64 | x86 | x64 | x86 | x64 | x64 | x86 | x64 | x86 | x64 | x64 | x86 | x86 | x64 | x86 | x64 | |
x86 offset offset:bitpos | Field Name | x64 offset offset:bitpos | ||||||||||||||||||||||||||||||||||
0x0000 | struct _DISPATCHER_HEADER Header | 0x0000 | ||||||||||||||||||||||||||||||||||
0x0010 | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | volatile uint64_t CycleTime | void * SListFaultAddress | 0x0018 | ||||||||||||||||||||||||||
0x0018 | void * InitialStack | void * InitialStack | volatile unsigned long HighCycleTime | volatile unsigned long HighCycleTime | volatile unsigned long HighCycleTime | volatile unsigned long HighCycleTime | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | 0x0020 | |||||||||||||||||
0x0018 | void * InitialStack | 0x0028 | ||||||||||||||||||||||||||||||||||
0x001C | void * StackLimit | void * volatile StackLimit | void * volatile StackLimit | 0x0030 | ||||||||||||||||||||||||||||||||
0x0020 | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | uint64_t QuantumTarget | 0x0020 | |||||||||||||||||||||||||
0x0020 | void * Teb | void * KernelStack | void * KernelStack | uint64_t QuantumTarget | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | 0x0028 | |||||||||||||||||||
0x0020 | void * KernelStack | 0x0038 | ||||||||||||||||||||||||||||||||||
0x0024 | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | 0x0030 | |||||||||||||||||||||||
0x0024 | void * TlsArray | uintptr_t ThreadLock | void * volatile StackLimit | 0x0040 | ||||||||||||||||||||||||||||||||
0x0028 | void * KernelStack | unsigned long ContextSwitches | struct _KAPC_STATE ApcState | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * InitialStack | void * StackBase | 0x0028 | |||||||||||||||||||||
0x0028 | uint8_t[23] ApcStateFill | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | 0x0038 | ||||||||||||||||||||||
0x0028 | struct _KAPC_STATE ApcState | 0x0048 | ||||||||||||||||||||||||||||||||||
0x0028 | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | 0x0048 | |||||||||||||||||||||||||||||
0x002C | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | void * volatile StackLimit | 0x0030 | |||||||||||||||||||||||||||
0x002C | uint8_t DebugActive | volatile uint8_t State | void * volatile StackLimit | uintptr_t ThreadLock | 0x0040 | |||||||||||||||||||||||||||||||
0x002D | uint8_t State | uint8_t NpxState | ||||||||||||||||||||||||||||||||||
0x002E | uint8_t[2] Alerted | uint8_t WaitIrql | ||||||||||||||||||||||||||||||||||
0x002F | char WaitMode | |||||||||||||||||||||||||||||||||||
0x0030 | void * KernelStack | void * KernelStack | void * KernelStack | void * KernelStack | void * KernelStack | void * KernelStack | void * KernelStack | void * KernelStack | 0x0038 | |||||||||||||||||||||||||||
0x0030 | uint8_t Iopl | void * Teb | void * KernelStack | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | volatile uint64_t CycleTime | 0x0048 | ||||||||||||||||||||
0x0031 | uint8_t NpxState | |||||||||||||||||||||||||||||||||||
0x0032 | char Saturation | |||||||||||||||||||||||||||||||||||
0x0033 | char Priority | |||||||||||||||||||||||||||||||||||
0x0034 | struct _KAPC_STATE ApcState | uintptr_t ThreadLock | 0x0040 | |||||||||||||||||||||||||||||||||
0x0038 | struct _KAPC_STATE ApcState | union _KWAIT_STATUS_REGISTER WaitRegister | volatile unsigned long HighCycleTime | volatile unsigned long HighCycleTime | volatile uint64_t CycleTime | volatile unsigned long HighCycleTime | volatile unsigned long HighCycleTime | volatile uint64_t CycleTime | volatile unsigned long HighCycleTime | volatile unsigned long HighCycleTime | 0x0048 | |||||||||||||||||||||||||
0x0038 | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | 0x0048 | |||||||||||||||||||||||||||||||||
0x0039 | volatile uint8_t Running | 0x0049 | ||||||||||||||||||||||||||||||||||
0x003A | uint8_t[2] Alerted | 0x004A | ||||||||||||||||||||||||||||||||||
0x003C:0x00 | unsigned long KernelStackResident | void * ServiceTable | void * ServiceTable | void * ServiceTable | void * ServiceTable | void * ServiceTable | void * ServiceTable | 0x004C:0x00 | ||||||||||||||||||||||||||||
0x003C | long MiscFlags | 0x004C | ||||||||||||||||||||||||||||||||||
0x003C:0x01 | unsigned long ReadyTransition | 0x004C:0x01 | ||||||||||||||||||||||||||||||||||
0x003C:0x02 | unsigned long ProcessReadyQueue | 0x004C:0x02 | ||||||||||||||||||||||||||||||||||
0x003C:0x03 | unsigned long WaitNext | 0x004C:0x03 | ||||||||||||||||||||||||||||||||||
0x003C:0x04 | unsigned long SystemAffinityActive | 0x004C:0x04 | ||||||||||||||||||||||||||||||||||
0x003C:0x05 | unsigned long Alertable | 0x004C:0x05 | ||||||||||||||||||||||||||||||||||
0x003C:0x06 | unsigned long GdiFlushActive | 0x004C:0x06 | ||||||||||||||||||||||||||||||||||
0x003C:0x07 | unsigned long UserStackWalkActive | 0x004C:0x07 | ||||||||||||||||||||||||||||||||||
0x003C:0x08 | unsigned long ApcInterruptRequest | 0x004C:0x08 | ||||||||||||||||||||||||||||||||||
0x003C:0x09 | unsigned long ForceDeferSchedule | 0x004C:0x09 | ||||||||||||||||||||||||||||||||||
0x003C:0x0A | unsigned long QuantumEndMigrate | 0x004C:0x0A | ||||||||||||||||||||||||||||||||||
0x003C:0x0B | unsigned long UmsDirectedSwitchEnable | 0x004C:0x0B | ||||||||||||||||||||||||||||||||||
0x003C:0x0C | unsigned long TimerActive | 0x004C:0x0C | ||||||||||||||||||||||||||||||||||
0x003C:0x0D | unsigned long Reserved | unsigned long Reserved | unsigned long Reserved | unsigned long Reserved | unsigned long SystemThread | 0x004C:0x0D | ||||||||||||||||||||||||||||||
0x003C:0x0E | unsigned long Reserved | unsigned long Reserved | 0x004C:0x0E | |||||||||||||||||||||||||||||||||
0x003F | uint8_t ApcQueueable | 0x0073 | ||||||||||||||||||||||||||||||||||
0x0040 | struct _KAPC_STATE ApcState | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | unsigned long CurrentRunTime | 0x0050 | ||||||||||||||||||||||
0x0040 | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | 0x0050 | |||||||||||||||||||||||||||||
0x0040 | volatile uint8_t NextProcessor | unsigned long CurrentRunTime | 0x0074 | |||||||||||||||||||||||||||||||||
0x0041 | volatile uint8_t DeferredProcessor | unsigned long QuantumEndMigrate | unsigned long QuantumEndMigrate | 0x0075 | ||||||||||||||||||||||||||||||||
0x0042 | uint8_t AdjustReason | 0x0076 | ||||||||||||||||||||||||||||||||||
0x0043 | char AdjustIncrement | 0x0077 | ||||||||||||||||||||||||||||||||||
0x0044 | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | unsigned long ExpectedRunTime | 0x0054 | |||||||||||||||||||||||
0x0044 | uintptr_t ApcQueueLock | unsigned long AutoAlignment | unsigned long AutoAlignment | unsigned long ExpectedRunTime | 0x0078 | |||||||||||||||||||||||||||||||
0x0048 | unsigned long ContextSwitches | void * KernelStack | 0x0058 | |||||||||||||||||||||||||||||||||
unsigned long ReservedFlags | 0x0078:0x17 | |||||||||||||||||||||||||||||||||||
unsigned long Spare1 | unsigned long Spare1 | unsigned long Spare1 | unsigned long Spare1 | unsigned long Spare10 | unsigned long Spare10 | unsigned long Spare10 | 0x0084 | |||||||||||||||||||||||||||||
unsigned long Spare0 | unsigned long Spare0 | unsigned long Spare0 | 0x0104 | |||||||||||||||||||||||||||||||||
0x0048 | unsigned long ContextSwitches | 0x0124 | ||||||||||||||||||||||||||||||||||
0x004C | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | struct _XSAVE_FORMAT * StateSaveArea | 0x0060 | |||||||||||||||||||||||
0x004C | unsigned long ContextSwitches | unsigned long ApcQueueLock | volatile uint8_t State | struct _XSAVE_FORMAT * StateSaveArea | 0x0154 | |||||||||||||||||||||||||||||||
0x004D | uint8_t NpxState | 0x0155 | ||||||||||||||||||||||||||||||||||
0x004E | uint8_t WaitIrql | 0x0156 | ||||||||||||||||||||||||||||||||||
0x004F | char Priority | char Priority | 0x0073 | |||||||||||||||||||||||||||||||||
0x004F | char WaitMode | char Priority | 0x0157 | |||||||||||||||||||||||||||||||||
0x0050 | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | 0x0068 | |||||||||||||||||||||||
0x0050 | uint8_t IdleSwapBlock | long WaitStatus | long WaitStatus | volatile uint16_t NextProcessor | volatile uint16_t NextProcessor | struct _KSCHEDULING_GROUP * volatile SchedulingGroup | 0x0074 | |||||||||||||||||||||||||||||
0x0050 | long WaitStatus | int64_t WaitStatus | long WaitStatus | int64_t WaitStatus | long WaitStatus | int64_t WaitStatus | 0x0080 | |||||||||||||||||||||||||||||
0x0051 | uint8_t[3] Spare0 | uint8_t VdmSafe | ||||||||||||||||||||||||||||||||||
0x0052 | uint8_t[2] Spare0 | volatile uint16_t DeferredProcessor | 0x0076 | |||||||||||||||||||||||||||||||||
0x0054 | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | union _KWAIT_STATUS_REGISTER WaitRegister | 0x0070 | |||||||||||||||||||||||
0x0054 | uintptr_t ApcQueueLock | uintptr_t ApcQueueLock | volatile long ThreadFlags | volatile long ThreadFlags | 0x0078 | |||||||||||||||||||||||||||||||
0x0054 | long WaitStatus | struct _KWAIT_BLOCK * WaitBlockList | struct _KWAIT_BLOCK * WaitBlockList | unsigned long ApcQueueLock | void * FirstArgument | void * FirstArgument | union _KWAIT_STATUS_REGISTER WaitRegister | 0x0088 | ||||||||||||||||||||||||||||
0x0054 | struct _KGATE * GateObject | struct _KGATE * GateObject | struct _KGATE * GateObject | struct _KGATE * GateObject | struct _KGATE * GateObject | struct _KGATE * GateObject | struct _KGATE * GateObject | 0x0088 | ||||||||||||||||||||||||||||
0x0055 | volatile uint8_t Running | 0x0071 | ||||||||||||||||||||||||||||||||||
0x0056 | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | 0x0072 | |||||||||||||||||||||||
0x0057 | char Priority | 0x007B | ||||||||||||||||||||||||||||||||||
0x0058:0x00 | uint8_t WaitIrql | uint8_t Alertable | uint8_t Alertable | unsigned long ContextSwitches | unsigned long KernelStackResident | unsigned long SpareMiscFlag0 | unsigned long AutoBoostActive | 0x0074:0x00 | ||||||||||||||||||||||||||||
0x0058 | long MiscFlags | long MiscFlags | long MiscFlags | long MiscFlags | long MiscFlags | long MiscFlags | long MiscFlags | long MiscFlags | long MiscFlags | long MiscFlags | long MiscFlags | long MiscFlags | 0x0074 | |||||||||||||||||||||||
0x0058 | volatile unsigned long NextProcessor | volatile unsigned long NextProcessor | volatile unsigned long NextProcessor | volatile unsigned long NextProcessor | volatile unsigned long NextProcessor | volatile unsigned long NextProcessor | unsigned long Spare0 | volatile uint8_t Tag | 0x007C | |||||||||||||||||||||||||||
0x0058 | uint8_t Alertable | uint8_t Alertable | uint8_t Alertable | uint8_t Alertable | uint8_t Alertable | uint8_t Alertable | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | 0x0090 | |||||||||||||||||||||||||||
0x0058 | unsigned long ContextSwitches | unsigned long ContextSwitches | 0x0124 | |||||||||||||||||||||||||||||||||
0x0058:0x01 | unsigned long ReadyTransition | 0x0074:0x01 | ||||||||||||||||||||||||||||||||||
0x0058:0x02 | unsigned long ProcessReadyQueue | unsigned long WaitNext | 0x0074:0x02 | |||||||||||||||||||||||||||||||||
0x0058:0x03 | unsigned long WaitNext | unsigned long SystemAffinityActive | 0x0074:0x03 | |||||||||||||||||||||||||||||||||
0x0058:0x04 | unsigned long SystemAffinityActive | unsigned long Alertable | 0x0074:0x04 | |||||||||||||||||||||||||||||||||
0x0058:0x05 | unsigned long Alertable | unsigned long UserStackWalkActive | 0x0074:0x05 | |||||||||||||||||||||||||||||||||
0x0058:0x06 | unsigned long CodePatchInProgress | unsigned long UserStackWalkActive | unsigned long ApcInterruptRequest | 0x0074:0x06 | ||||||||||||||||||||||||||||||||
0x0058:0x07 | unsigned long UserStackWalkActive | unsigned long ApcInterruptRequest | unsigned long QuantumEndMigrate | 0x0074:0x07 | ||||||||||||||||||||||||||||||||
0x0058:0x08 | char WaitMode | uint8_t WaitNext | uint8_t WaitNext | unsigned long ApcInterruptRequest | unsigned long ApcInterruptRequest | unsigned long ApcInterruptRequest | unsigned long ApcInterruptRequest | unsigned long QuantumEndMigrate | unsigned long QuantumEndMigrate | unsigned long QuantumEndMigrate | unsigned long QuantumEndMigrate | unsigned long QuantumEndMigrate | unsigned long QuantumEndMigrate | unsigned long UmsDirectedSwitchEnable | unsigned long UmsDirectedSwitchEnable | 0x0074:0x08 | ||||||||||||||||||||
0x0059 | uint8_t WaitNext | uint8_t WaitNext | uint8_t WaitNext | uint8_t WaitNext | uint8_t WaitNext | uint8_t WaitNext | 0x0091 | |||||||||||||||||||||||||||||
0x0058:0x09 | unsigned long QuantumEndMigrate | unsigned long UmsDirectedSwitchEnable | unsigned long TimerActive | 0x0074:0x09 | ||||||||||||||||||||||||||||||||
0x0058:0x0A | unsigned long UmsDirectedSwitchEnable | unsigned long TimerActive | unsigned long SystemThread | 0x0074:0x0A | ||||||||||||||||||||||||||||||||
0x0058:0x0B | unsigned long TimerActive | unsigned long SystemThread | unsigned long ProcessDetachActive | 0x0074:0x0B | ||||||||||||||||||||||||||||||||
0x0058:0x0C | unsigned long SystemThread | unsigned long ProcessDetachActive | unsigned long CalloutActive | 0x0074:0x0C | ||||||||||||||||||||||||||||||||
0x0058:0x0D | unsigned long ProcessDetachActive | unsigned long CalloutActive | unsigned long ScbReadyQueue | 0x0074:0x0D | ||||||||||||||||||||||||||||||||
0x0058:0x0E | unsigned long CalloutActive | unsigned long ScbReadyQueue | unsigned long ApcQueueable | 0x0074:0x0E | ||||||||||||||||||||||||||||||||
0x0058:0x0F | unsigned long ScbReadyQueue | unsigned long ApcQueueable | unsigned long ReservedStackInUse | 0x0074:0x0F | ||||||||||||||||||||||||||||||||
0x0058:0x10 | unsigned long ApcQueueable | unsigned long ApcQueueable | unsigned long ApcQueueable | unsigned long ApcQueueable | unsigned long ReservedStackInUse | unsigned long ReservedStackInUse | unsigned long ReservedStackInUse | unsigned long ReservedStackInUse | unsigned long ReservedStackInUse | unsigned long ReservedStackInUse | unsigned long ReservedStackInUse | unsigned long UmsPerformingSyscall | unsigned long UmsPerformingSyscall | 0x0074:0x10 | ||||||||||||||||||||||
0x005A | uint8_t WaitNext | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | unsigned long ReservedStackInUse | 0x0092 | ||||||||||||||||||||||||||
0x0058:0x11 | unsigned long ReservedStackInUse | unsigned long UmsPerformingSyscall | unsigned long TimerSuspended | 0x0074:0x11 | ||||||||||||||||||||||||||||||||
0x0058:0x12 | unsigned long UmsPerformingSyscall | unsigned long ApcPendingReload | unsigned long SuspendedWaitMode | 0x0074:0x12 | ||||||||||||||||||||||||||||||||
0x0058:0x13 | unsigned long DisableStackCheck | unsigned long Reserved | unsigned long Reserved | unsigned long Reserved | unsigned long Reserved | unsigned long TimerSuspended | unsigned long SuspendSchedulerApcWait | 0x0074:0x13 | ||||||||||||||||||||||||||||
0x0058:0x14 | unsigned long Reserved | unsigned long Reserved | unsigned long SuspendedWaitMode | unsigned long Reserved | unsigned long Reserved | 0x0074:0x14 | ||||||||||||||||||||||||||||||
0x0058:0x15 | unsigned long Reserved | unsigned long Reserved | unsigned long Reserved | unsigned long SuspendSchedulerApcWait | 0x0074:0x15 | |||||||||||||||||||||||||||||||
0x0058:0x16 | unsigned long Reserved | unsigned long Reserved | 0x0074:0x16 | |||||||||||||||||||||||||||||||||
0x005B | uint8_t WaitReason | char Priority | 0x0093 | |||||||||||||||||||||||||||||||||
0x005C:0x00 | volatile unsigned long AutoAlignment | unsigned long AutoAlignment | unsigned long AutoAlignment | unsigned long AutoAlignment | 0x0078:0x00 | |||||||||||||||||||||||||||||||
0x005C | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | volatile long ThreadFlags | 0x0078 | |||||||||||||||||||||||
0x005C | volatile unsigned long DeferredProcessor | volatile unsigned long DeferredProcessor | volatile unsigned long DeferredProcessor | volatile unsigned long DeferredProcessor | volatile unsigned long DeferredProcessor | volatile unsigned long DeferredProcessor | unsigned long SystemCallNumber | unsigned long SystemCallNumber | 0x0080 | |||||||||||||||||||||||||||
0x005C | uint8_t EnableStackSwap | uint8_t EnableStackSwap | uint8_t EnableStackSwap | uint8_t EnableStackSwap | uint8_t EnableStackSwap | uint8_t EnableStackSwap | volatile long ThreadFlags | 0x0094 | ||||||||||||||||||||||||||||
0x005C | struct _KWAIT_BLOCK * WaitBlockList | uint8_t EnableStackSwap | uint8_t EnableStackSwap | volatile uint8_t State | volatile uint8_t State | unsigned long ContextSwitches | unsigned long ContextSwitches | unsigned long AutoAlignment | 0x0154 | |||||||||||||||||||||||||||
0x005C:0x01 | volatile unsigned long DisableBoost | unsigned long DisableBoost | 0x0078:0x01 | |||||||||||||||||||||||||||||||||
0x005C:0x02 | volatile unsigned long UserAffinitySet | unsigned long UserAffinitySet | unsigned long ThreadFlagsSpare0 | 0x0078:0x02 | ||||||||||||||||||||||||||||||||
0x005C:0x03 | volatile unsigned long AlertedByThreadId | unsigned long AlertedByThreadId | 0x0078:0x03 | |||||||||||||||||||||||||||||||||
0x005C:0x04 | volatile unsigned long QuantumDonation | unsigned long QuantumDonation | 0x0078:0x04 | |||||||||||||||||||||||||||||||||
0x005C:0x05 | volatile unsigned long EnableStackSwap | unsigned long EnableStackSwap | 0x0078:0x05 | |||||||||||||||||||||||||||||||||
0x005C:0x06 | volatile unsigned long GuiThread | unsigned long GuiThread | 0x0078:0x06 | |||||||||||||||||||||||||||||||||
0x005C:0x07 | volatile unsigned long DisableQuantum | unsigned long DisableQuantum | 0x0078:0x07 | |||||||||||||||||||||||||||||||||
0x005C:0x08 | volatile unsigned long ChargeOnlyGroup | volatile unsigned long ChargeOnlyGroup | unsigned long ChargeOnlyGroup | unsigned long ChargeOnlyGroup | unsigned long ChargeOnlySchedulingGroup | unsigned long ChargeOnlySchedulingGroup | unsigned long ChargeOnlySchedulingGroup | unsigned long ChargeOnlySchedulingGroup | unsigned long ChargeOnlySchedulingGroup | unsigned long ChargeOnlySchedulingGroup | unsigned long ChargeOnlySchedulingGroup | unsigned long ChargeOnlySchedulingGroup | unsigned long ChargeOnlySchedulingGroup | 0x0078:0x08 | ||||||||||||||||||||||
0x005D | volatile uint8_t SwapBusy | volatile uint8_t SwapBusy | volatile uint8_t SwapBusy | volatile uint8_t SwapBusy | volatile uint8_t SwapBusy | volatile uint8_t SwapBusy | volatile uint8_t SwapBusy | uint8_t NpxState | unsigned long ChargeOnlySchedulingGroup | 0x0095 | ||||||||||||||||||||||||||
0x005D | uint8_t NpxState | uint8_t NpxState | 0x0155 | |||||||||||||||||||||||||||||||||
0x005C:0x09 | volatile unsigned long DeferPreemption | unsigned long DeferPreemption | 0x0078:0x09 | |||||||||||||||||||||||||||||||||
0x005C:0x0A | volatile unsigned long QueueDeferPreemption | unsigned long QueueDeferPreemption | 0x0078:0x0A | |||||||||||||||||||||||||||||||||
0x005C:0x0B | volatile unsigned long ForceDeferSchedule | unsigned long ForceDeferSchedule | 0x0078:0x0B | |||||||||||||||||||||||||||||||||
0x005C:0x0C | volatile unsigned long ExplicitIdealProcessor | unsigned long ExplicitIdealProcessor | unsigned long SharedReadyQueueAffinity | 0x0078:0x0C | ||||||||||||||||||||||||||||||||
0x005C:0x0D | volatile unsigned long FreezeCount | unsigned long FreezeCount | 0x0078:0x0D | |||||||||||||||||||||||||||||||||
0x005C:0x0E | volatile unsigned long EtwStackTraceApcInserted | volatile unsigned long EtwStackTraceApcInserted | unsigned long EtwStackTraceApcInserted | unsigned long EtwStackTraceApcInserted | unsigned long TerminationApcRequest | 0x0078:0x0E | ||||||||||||||||||||||||||||||
0x005C:0x0F | unsigned long EtwStackTraceApcInserted | unsigned long AutoBoostEntriesExhausted | 0x0078:0x0F | |||||||||||||||||||||||||||||||||
0x005C:0x10 | unsigned long EtwStackTraceApcInserted | unsigned long EtwStackTraceApcInserted | unsigned long KernelStackResident | unsigned long KernelStackResident | unsigned long KernelStackResident | unsigned long KernelStackResident | unsigned long KernelStackResident | unsigned long KernelStackResident | 0x0078:0x10 | |||||||||||||||||||||||||||
0x005E | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t[2] Alerted | 0x0096 | |||||||||||||||||||||||||||||
0x005E | uint8_t[2] Alerted | uint8_t[2] Alerted | uint8_t WaitIrql | uint8_t WaitIrql | unsigned long KernelStackResident | 0x0156 | ||||||||||||||||||||||||||||||
0x005C:0x11 | unsigned long EtwStackTraceApcInserted | unsigned long EtwStackTraceApcInserted | unsigned long ThreadFlagsSpare | unsigned long CommitFailTerminateRequest | 0x0078:0x11 | |||||||||||||||||||||||||||||||
0x005C:0x12 | unsigned long ThreadFlagsSpare | unsigned long ProcessStackCountDecremented | 0x0078:0x12 | |||||||||||||||||||||||||||||||||
0x005C:0x13 | unsigned long ThreadFlagsSpare | 0x0078:0x13 | ||||||||||||||||||||||||||||||||||
0x005C:0x16 | volatile unsigned long ReservedFlags | volatile unsigned long ReservedFlags | unsigned long ReservedFlags | unsigned long ReservedFlags | 0x0078:0x16 | |||||||||||||||||||||||||||||||
0x005C:0x18 | char WaitMode | unsigned long ReservedFlags | unsigned long ReservedFlags | unsigned long EtwStackTraceApcInserted | unsigned long EtwStackTraceApcInserted | unsigned long EtwStackTraceApcInserted | unsigned long EtwStackTraceApcInserted | unsigned long EtwStackTraceApcInserted | 0x0078:0x18 | |||||||||||||||||||||||||||
0x005F | char WaitMode | char WaitMode | 0x0157 | |||||||||||||||||||||||||||||||||
0x005C:0x19 | unsigned long ReservedFlags | 0x0078:0x19 | ||||||||||||||||||||||||||||||||||
0x0060 | unsigned long Spare0 | unsigned long Spare0 | unsigned long Spare0 | unsigned long Spare0 | unsigned long Spare0 | unsigned long Spare0 | unsigned long Spare0 | unsigned long Spare0 | volatile uint8_t Tag | volatile uint8_t Tag | volatile uint8_t Tag | volatile uint8_t Tag | 0x007C | |||||||||||||||||||||||
0x0060 | long WaitStatus | int64_t WaitStatus | 0x0080 | |||||||||||||||||||||||||||||||||
0x0060 | uintptr_t ApcQueueLock | uintptr_t ApcQueueLock | uintptr_t ApcQueueLock | uintptr_t ApcQueueLock | uintptr_t ApcQueueLock | uintptr_t ApcQueueLock | 0x0088 | |||||||||||||||||||||||||||||
0x0060 | struct _LIST_ENTRY WaitListEntry | long WaitStatus | volatile uint8_t Tag | 0x0098 | ||||||||||||||||||||||||||||||||
0x0060 | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | 0x0098 | ||||||||||||||||||||||||||||
0x0061 | uint8_t SystemHeteroCpuPolicy | 0x007D | ||||||||||||||||||||||||||||||||||
0x0062:0x00 | uint8_t UserHeteroCpuPolicy | 0x007E:0x00 | ||||||||||||||||||||||||||||||||||
0x0062:0x07 | uint8_t ExplicitSystemHeteroCpuPolicy | 0x007E:0x07 | ||||||||||||||||||||||||||||||||||
0x0063 | uint8_t[1] Spare0 | uint8_t Spare0 | 0x007F | |||||||||||||||||||||||||||||||||
0x0064 | struct _KGATE * GateObject | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | 0x0080 | ||||||||||||||||||||||
0x0064 | struct _KWAIT_BLOCK * WaitBlockList | 0x0088 | ||||||||||||||||||||||||||||||||||
0x0064 | struct _KGATE * GateObject | struct _KGATE * GateObject | 0x0088 | |||||||||||||||||||||||||||||||||
0x0064 | struct _KWAIT_BLOCK * WaitBlockList | unsigned long ContextSwitches | unsigned long SystemCallNumber | 0x0134 | ||||||||||||||||||||||||||||||||
0x0068 | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | 0x0088 | |||||||||||||||||||||||
0x0068:0x00 | unsigned long KernelStackResident | 0x0090:0x00 | ||||||||||||||||||||||||||||||||||
0x0068 | long MiscFlags | long MiscFlags | 0x0090 | |||||||||||||||||||||||||||||||||
0x0068 | struct _KQUEUE * Queue | struct _KQUEUE * Queue | struct _KQUEUE * Queue | struct _KQUEUE * Queue | struct _KQUEUE * Queue | struct _KQUEUE * Queue | long MiscFlags | 0x00A8 | ||||||||||||||||||||||||||||
0x0068 | unsigned long WaitTime | struct _KQUEUE * Queue | struct _KQUEUE * Queue | unsigned long KernelStackResident | volatile uint8_t State | volatile uint8_t State | volatile uint8_t State | volatile uint8_t State | volatile uint8_t State | volatile uint8_t State | void * FirstArgument | 0x0164 | ||||||||||||||||||||||||
0x0068:0x01 | unsigned long ReadyTransition | 0x0090:0x01 | ||||||||||||||||||||||||||||||||||
0x0068:0x02 | unsigned long ProcessReadyQueue | 0x0090:0x02 | ||||||||||||||||||||||||||||||||||
0x0068:0x03 | unsigned long WaitNext | 0x0090:0x03 | ||||||||||||||||||||||||||||||||||
0x0068:0x04 | unsigned long SystemAffinityActive | 0x0090:0x04 | ||||||||||||||||||||||||||||||||||
0x0068:0x05 | unsigned long Alertable | 0x0090:0x05 | ||||||||||||||||||||||||||||||||||
0x0068:0x06 | unsigned long GdiFlushActive | 0x0090:0x06 | ||||||||||||||||||||||||||||||||||
0x0068:0x07 | unsigned long Reserved | unsigned long UserStackWalkActive | 0x0090:0x07 | |||||||||||||||||||||||||||||||||
0x0068:0x08 | unsigned long Reserved | unsigned long Reserved | 0x0090:0x08 | |||||||||||||||||||||||||||||||||
0x0069 | unsigned long Reserved | char NpxState | 0x0165 | |||||||||||||||||||||||||||||||||
0x006A | uint8_t WaitIrql | 0x0166 | ||||||||||||||||||||||||||||||||||
0x006B | char WaitMode | 0x0167 | ||||||||||||||||||||||||||||||||||
0x006C | char BasePriority | unsigned long WaitTime | unsigned long WaitTime | uint8_t WaitReason | volatile long WaitStatus | volatile int64_t WaitStatus | volatile long WaitStatus | volatile int64_t WaitStatus | volatile long WaitStatus | volatile int64_t WaitStatus | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | 0x0090 | |||||||||||||
0x006C | uint8_t WaitReason | uint8_t WaitReason | 0x0094 | |||||||||||||||||||||||||||||||||
0x006C | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | 0x0184 | |||||||||||||||||||||||||||||
0x006D | uint8_t DecrementCount | volatile uint8_t SwapBusy | 0x0095 | |||||||||||||||||||||||||||||||||
0x006E | char PriorityDecrement | uint8_t[2] Alerted | 0x0096 | |||||||||||||||||||||||||||||||||
0x006F | char Quantum | |||||||||||||||||||||||||||||||||||
0x0070 | struct _KWAIT_BLOCK[4] WaitBlock | int16_t KernelApcDisable | int16_t KernelApcDisable | struct _LIST_ENTRY WaitListEntry | struct _KWAIT_BLOCK * WaitBlockList | struct _KAPC_STATE ApcState | 0x0098 | |||||||||||||||||||||||||||||
0x0070 | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | struct _SINGLE_LIST_ENTRY SwapListEntry | x86: uint8_t[23] / x64: uint8_t[43] ApcStateFill | 0x0098 | |||||||||||||||||||||||||||||||
void * TebMappedLowVa | void * TebMappedLowVa | void * TebMappedLowVa | 0x01B0 | |||||||||||||||||||||||||||||||||
0x0070 | int16_t KernelApcDisable | 0x01B4 | ||||||||||||||||||||||||||||||||||
0x0070 | unsigned long CombinedApcDisable | 0x01B4 | ||||||||||||||||||||||||||||||||||
0x0072 | int16_t SpecialApcDisable | 0x01B6 | ||||||||||||||||||||||||||||||||||
0x0074 | struct _LIST_ENTRY WaitListEntry | 0x00A0 | ||||||||||||||||||||||||||||||||||
0x0074 | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | struct _SINGLE_LIST_ENTRY SwapListEntry | 0x00A0 | |||||||||||||||||||||||||||||
0x0074 | void * Teb | 0x00B0 | ||||||||||||||||||||||||||||||||||
0x0078 | struct _KQUEUE * Queue | struct _KQUEUE * Queue | 0x00A8 | |||||||||||||||||||||||||||||||||
0x0078 | struct _KTIMER Timer | struct _KTIMER Timer | struct _KQUEUE * Queue | 0x00B8 | ||||||||||||||||||||||||||||||||
0x0078 | x86: uint8_t[40] / x64: uint8_t[60] TimerFill | x86: uint8_t[40] / x64: uint8_t[60] TimerFill | x86: uint8_t[40] / x64: uint8_t[60] TimerFill | x86: uint8_t[40] / x64: uint8_t[60] TimerFill | x86: uint8_t[40] / x64: uint8_t[60] TimerFill | x86: uint8_t[40] / x64: uint8_t[60] TimerFill | x86: uint8_t[40] / x64: uint8_t[60] TimerFill | 0x00B8 | ||||||||||||||||||||||||||||
0x007C | unsigned long WaitTime | struct _KQUEUE * volatile Queue | struct _KQUEUE * volatile Queue | struct _KQUEUE * volatile Queue | struct _KQUEUE * volatile Queue | struct _KQUEUE * volatile Queue | struct _KQUEUE * volatile Queue | 0x00B0 | ||||||||||||||||||||||||||||
0x007C | unsigned long WaitTime | 0x0184 | ||||||||||||||||||||||||||||||||||
0x0080 | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | 0x0194 | |||||||||||||||||||||||||||||
0x0080 | int16_t KernelApcDisable | 0x01B4 | ||||||||||||||||||||||||||||||||||
0x0080 | unsigned long CombinedApcDisable | 0x01B4 | ||||||||||||||||||||||||||||||||||
0x0082 | int16_t SpecialApcDisable | 0x01B6 | ||||||||||||||||||||||||||||||||||
0x0084 | void * Teb | void * Teb | 0x00B0 | |||||||||||||||||||||||||||||||||
0x0084 | int16_t KernelApcDisable | 0x01C4 | ||||||||||||||||||||||||||||||||||
0x0084 | unsigned long CombinedApcDisable | 0x01C4 | ||||||||||||||||||||||||||||||||||
0x0086 | int16_t SpecialApcDisable | int16_t SpecialApcDisable | int16_t SpecialApcDisable | int16_t SpecialApcDisable | int16_t SpecialApcDisable | int16_t SpecialApcDisable | 0x01C6 | |||||||||||||||||||||||||||||
0x0087 | char Priority | 0x00C3 | ||||||||||||||||||||||||||||||||||
0x0088 | struct _KTIMER Timer | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | unsigned long UserIdealProcessor | 0x00B8 | |||||||||||||||||||||||||||
0x0088 | x86: uint8_t[40] / x64: uint8_t[60] TimerFill | x86: uint8_t[40] / x64: uint8_t[60] TimerFill | 0x00B8 | |||||||||||||||||||||||||||||||||
0x0088 | unsigned long UserIdealProcessor | unsigned long UserIdealProcessor | 0x00C4 | |||||||||||||||||||||||||||||||||
0x008C | unsigned long ContextSwitches | unsigned long ContextSwitches | 0x014C | |||||||||||||||||||||||||||||||||
0x008C | unsigned long ContextSwitches | unsigned long ContextSwitches | unsigned long ContextSwitches | 0x0154 | ||||||||||||||||||||||||||||||||
0x0090 | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | 0x00C0 | |||||||||||||||||||||||||||||
0x0090 | volatile uint8_t State | volatile uint8_t State | volatile uint8_t State | 0x017C | ||||||||||||||||||||||||||||||||
0x0090 | volatile uint8_t State | volatile uint8_t State | 0x0184 | |||||||||||||||||||||||||||||||||
0x0091 | char NpxState | char NpxState | 0x017D | |||||||||||||||||||||||||||||||||
0x0091 | char NpxState | char Spare12 | char Spare13 | 0x0185 | ||||||||||||||||||||||||||||||||
0x0092 | uint8_t WaitIrql | uint8_t WaitIrql | 0x017E | |||||||||||||||||||||||||||||||||
0x0092 | uint8_t WaitIrql | 0x0186 | ||||||||||||||||||||||||||||||||||
0x0093 | char WaitMode | char WaitMode | char WaitMode | 0x017F | ||||||||||||||||||||||||||||||||
0x0093 | char WaitMode | char WaitMode | 0x0187 | |||||||||||||||||||||||||||||||||
0x0094 | volatile long WaitStatus | volatile int64_t WaitStatus | volatile long WaitStatus | volatile int64_t WaitStatus | volatile long WaitStatus | volatile int64_t WaitStatus | volatile long WaitStatus | volatile int64_t WaitStatus | volatile long WaitStatus | volatile int64_t WaitStatus | volatile long WaitStatus | volatile int64_t WaitStatus | 0x00C8 | |||||||||||||||||||||||
0x0098 | struct _KWAIT_BLOCK * WaitBlockList | 0x00D0 | ||||||||||||||||||||||||||||||||||
0x009C | struct _LIST_ENTRY WaitListEntry | 0x00D8 | ||||||||||||||||||||||||||||||||||
0x009C | struct _SINGLE_LIST_ENTRY SwapListEntry | 0x00D8 | ||||||||||||||||||||||||||||||||||
0x00A0:0x00 | struct _KWAIT_BLOCK[4] WaitBlock | long AutoAlignment | unsigned long AutoAlignment | 0x00F4:0x00 | ||||||||||||||||||||||||||||||||
0x00A0 | long ThreadFlags | 0x00F4 | ||||||||||||||||||||||||||||||||||
0x00A0:0x01 | long DisableBoost | unsigned long DisableBoost | 0x00F4:0x01 | |||||||||||||||||||||||||||||||||
0x00A0:0x02 | long ReservedFlags | unsigned long GuiThread | 0x00F4:0x02 | |||||||||||||||||||||||||||||||||
0x00A0:0x03 | unsigned long ReservedFlags | unsigned long VdmSafe | unsigned long EtwStackTraceApc1Inserted | 0x00F4:0x03 | ||||||||||||||||||||||||||||||||
0x00A0:0x04 | unsigned long ReservedFlags | unsigned long VdmSafe | 0x00F4:0x04 | |||||||||||||||||||||||||||||||||
0x00A0:0x05 | unsigned long ReservedFlags | |||||||||||||||||||||||||||||||||||
0x00A4 | struct _KQUEUE * volatile Queue | struct _DISPATCHER_HEADER * volatile Queue | 0x00E8 | |||||||||||||||||||||||||||||||||
0x00A8 | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | void * Teb | 0x00F0 | |||||||||||||||||||||||
0x00A8 | struct _KWAIT_BLOCK[4] WaitBlock | void * Teb | 0x00F8 | |||||||||||||||||||||||||||||||||
0x00A8 | x86: uint8_t[23] / x64: uint8_t[43] WaitBlockFill0 | 0x00F8 | ||||||||||||||||||||||||||||||||||
0x00A8 | x86: uint8_t[47] / x64: uint8_t[91] WaitBlockFill1 | 0x00F8 | ||||||||||||||||||||||||||||||||||
0x00A8 | x86: uint8_t[71] / x64: uint8_t[139] WaitBlockFill2 | 0x00F8 | ||||||||||||||||||||||||||||||||||
0x00A8 | x86: uint8_t[95] / x64: uint8_t[187] WaitBlockFill3 | x86: uint8_t[95] / x64: uint8_t[187] WaitBlockFill3 | x86: uint8_t[95] / x64: uint8_t[187] WaitBlockFill3 | x86: uint8_t[95] / x64: uint8_t[187] WaitBlockFill3 | x86: uint8_t[95] / x64: uint8_t[187] WaitBlockFill3 | x86: uint8_t[95] / x64: uint8_t[187] WaitBlockFill3 | x86: uint8_t[95] / x64: uint8_t[187] WaitBlockFill3 | 0x00F8 | ||||||||||||||||||||||||||||
uint8_t[44] WaitBlockFill4 | uint8_t[44] WaitBlockFill4 | uint8_t[44] WaitBlockFill4 | 0x00F8 | |||||||||||||||||||||||||||||||||
uint8_t[92] WaitBlockFill5 | uint8_t[92] WaitBlockFill5 | uint8_t[92] WaitBlockFill5 | 0x00F8 | |||||||||||||||||||||||||||||||||
uint8_t[140] WaitBlockFill6 | uint8_t[140] WaitBlockFill6 | uint8_t[140] WaitBlockFill6 | 0x00F8 | |||||||||||||||||||||||||||||||||
uint8_t[188] WaitBlockFill7 | uint8_t[188] WaitBlockFill7 | uint8_t[188] WaitBlockFill7 | 0x00F8 | |||||||||||||||||||||||||||||||||
0x00B0:0x00 | volatile unsigned long AutoAlignment | uint64_t RelativeTimerBias | 0x00F4:0x00 | |||||||||||||||||||||||||||||||||
0x00B0 | volatile long ThreadFlags | volatile long ThreadFlags | 0x00F4 | |||||||||||||||||||||||||||||||||
0x00B0 | struct _KTIMER Timer | struct _KTIMER Timer | uint64_t RelativeTimerBias | uint64_t RelativeTimerBias | uint64_t RelativeTimerBias | uint64_t RelativeTimerBias | uint64_t RelativeTimerBias | uint64_t RelativeTimerBias | uint64_t RelativeTimerBias | uint64_t RelativeTimerBias | uint64_t RelativeTimerBias | uint64_t RelativeTimerBias | 0x00F8 | |||||||||||||||||||||||
0x00B0:0x01 | volatile unsigned long DisableBoost | 0x00F4:0x01 | ||||||||||||||||||||||||||||||||||
0x00B0:0x02 | volatile unsigned long EtwStackTraceApc1Inserted | 0x00F4:0x02 | ||||||||||||||||||||||||||||||||||
0x00B0:0x03 | volatile unsigned long EtwStackTraceApc2Inserted | 0x00F4:0x03 | ||||||||||||||||||||||||||||||||||
0x00B0:0x04 | volatile unsigned long CycleChargePending | 0x00F4:0x04 | ||||||||||||||||||||||||||||||||||
0x00B0:0x05 | volatile unsigned long CalloutActive | 0x00F4:0x05 | ||||||||||||||||||||||||||||||||||
0x00B0:0x06 | volatile unsigned long ApcQueueable | 0x00F4:0x06 | ||||||||||||||||||||||||||||||||||
0x00B0:0x07 | volatile unsigned long EnableStackSwap | 0x00F4:0x07 | ||||||||||||||||||||||||||||||||||
0x00B0:0x08 | volatile unsigned long GuiThread | 0x00F4:0x08 | ||||||||||||||||||||||||||||||||||
0x00B0:0x09 | volatile unsigned long ReservedFlags | volatile unsigned long VdmSafe | 0x00F4:0x09 | |||||||||||||||||||||||||||||||||
0x00B0:0x0A | volatile unsigned long ReservedFlags | 0x00F4:0x0A | ||||||||||||||||||||||||||||||||||
0x00B8 | struct _KWAIT_BLOCK[4] WaitBlock | struct _KTIMER Timer | 0x00F8 | |||||||||||||||||||||||||||||||||
0x00B8 | x86: uint8_t[23] / x64: uint8_t[43] WaitBlockFill0 | 0x00F8 | ||||||||||||||||||||||||||||||||||
0x00B8 | x86: uint8_t[47] / x64: uint8_t[91] WaitBlockFill1 | 0x00F8 | ||||||||||||||||||||||||||||||||||
0x00B8 | x86: uint8_t[71] / x64: uint8_t[139] WaitBlockFill2 | 0x00F8 | ||||||||||||||||||||||||||||||||||
0x00B8 | x86: uint8_t[95] / x64: uint8_t[187] WaitBlockFill3 | x86: uint8_t[95] / x64: uint8_t[187] WaitBlockFill3 | 0x00F8 | |||||||||||||||||||||||||||||||||
uint8_t[44] WaitBlockFill4 | 0x00F8 | |||||||||||||||||||||||||||||||||||
uint8_t[92] WaitBlockFill5 | 0x00F8 | |||||||||||||||||||||||||||||||||||
uint8_t[140] WaitBlockFill6 | 0x00F8 | |||||||||||||||||||||||||||||||||||
uint8_t[188] WaitBlockFill7 | 0x00F8 | |||||||||||||||||||||||||||||||||||
0x00B8:0x00 | volatile unsigned long AutoAlignment | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | struct _KTIMER Timer | 0x0100:0x00 | ||||||||||||||||||||||||
0x00B8 | volatile long ThreadFlags | 0x0100 | ||||||||||||||||||||||||||||||||||
0x00B8:0x01 | volatile unsigned long DisableBoost | 0x0100:0x01 | ||||||||||||||||||||||||||||||||||
0x00B8:0x02 | volatile unsigned long EtwStackTraceApc1Inserted | 0x0100:0x02 | ||||||||||||||||||||||||||||||||||
0x00B8:0x03 | volatile unsigned long EtwStackTraceApc2Inserted | 0x0100:0x03 | ||||||||||||||||||||||||||||||||||
0x00B8:0x04 | volatile unsigned long CalloutActive | 0x0100:0x04 | ||||||||||||||||||||||||||||||||||
0x00B8:0x05 | volatile unsigned long ApcQueueable | 0x0100:0x05 | ||||||||||||||||||||||||||||||||||
0x00B8:0x06 | volatile unsigned long EnableStackSwap | 0x0100:0x06 | ||||||||||||||||||||||||||||||||||
0x00B8:0x07 | volatile unsigned long GuiThread | 0x0100:0x07 | ||||||||||||||||||||||||||||||||||
0x00B8:0x08 | volatile unsigned long UmsPerformingSyscall | 0x0100:0x08 | ||||||||||||||||||||||||||||||||||
0x00B8:0x09 | volatile unsigned long ReservedFlags | volatile unsigned long VdmSafe | 0x0100:0x09 | |||||||||||||||||||||||||||||||||
0x00B8:0x0A | volatile unsigned long ReservedFlags | volatile unsigned long UmsDispatched | 0x0100:0x0A | |||||||||||||||||||||||||||||||||
0x00B8:0x0B | volatile unsigned long ReservedFlags | 0x0100:0x0B | ||||||||||||||||||||||||||||||||||
0x00BC | void * ServiceTable | void * ServiceTable | void * ServiceTable | |||||||||||||||||||||||||||||||||
0x00BF | uint8_t SystemAffinityActive | 0x0123 | ||||||||||||||||||||||||||||||||||
0x00C0 | struct _KWAIT_BLOCK[4] WaitBlock | struct _KWAIT_BLOCK[4] WaitBlock | struct _KWAIT_BLOCK[4] WaitBlock | struct _KWAIT_BLOCK[4] WaitBlock | struct _KWAIT_BLOCK[4] WaitBlock | struct _KWAIT_BLOCK[4] WaitBlock | 0x0108 | |||||||||||||||||||||||||||||
uint8_t[44] WaitBlockFill4 | uint8_t[44] WaitBlockFill4 | uint8_t[44] WaitBlockFill4 | 0x0108 | |||||||||||||||||||||||||||||||||
uint8_t[92] WaitBlockFill5 | uint8_t[92] WaitBlockFill5 | uint8_t[92] WaitBlockFill5 | 0x0108 | |||||||||||||||||||||||||||||||||
uint8_t[140] WaitBlockFill6 | uint8_t[140] WaitBlockFill6 | uint8_t[140] WaitBlockFill6 | 0x0108 | |||||||||||||||||||||||||||||||||
uint8_t[168] WaitBlockFill7 | uint8_t[168] WaitBlockFill7 | uint8_t[168] WaitBlockFill7 | 0x0108 | |||||||||||||||||||||||||||||||||
uint8_t[188] WaitBlockFill8 | uint8_t[188] WaitBlockFill8 | uint8_t[188] WaitBlockFill8 | 0x0108 | |||||||||||||||||||||||||||||||||
0x00CF | uint8_t IdealProcessor | 0x0123 | ||||||||||||||||||||||||||||||||||
0x00D0 | void * LegoData | |||||||||||||||||||||||||||||||||||
0x00D4 | unsigned long KernelApcDisable | |||||||||||||||||||||||||||||||||||
0x00D7 | char PreviousMode | 0x0153 | ||||||||||||||||||||||||||||||||||
0x00D8 | unsigned long UserAffinity | struct _KWAIT_BLOCK[4] WaitBlock | 0x0138 | |||||||||||||||||||||||||||||||||
0x00D8 | uint8_t[20] WaitBlockFill8 | uint8_t[20] WaitBlockFill4 | 0x0138 | |||||||||||||||||||||||||||||||||
0x00D8 | uint8_t[44] WaitBlockFill9 | uint8_t[68] WaitBlockFill5 | 0x0138 | |||||||||||||||||||||||||||||||||
0x00D8 | uint8_t[68] WaitBlockFill10 | uint8_t[116] WaitBlockFill6 | 0x0138 | |||||||||||||||||||||||||||||||||
0x00D8 | uint8_t[88] WaitBlockFill11 | uint8_t[164] WaitBlockFill7 | 0x0138 | |||||||||||||||||||||||||||||||||
uint8_t[40] WaitBlockFill8 | 0x0138 | |||||||||||||||||||||||||||||||||||
uint8_t[88] WaitBlockFill9 | 0x0138 | |||||||||||||||||||||||||||||||||||
uint8_t[136] WaitBlockFill10 | 0x0138 | |||||||||||||||||||||||||||||||||||
uint8_t[176] WaitBlockFill11 | 0x0138 | |||||||||||||||||||||||||||||||||||
0x00DC | uint8_t SystemAffinityActive | |||||||||||||||||||||||||||||||||||
0x00DD | uint8_t PowerState | |||||||||||||||||||||||||||||||||||
0x00DE | uint8_t NpxIrql | |||||||||||||||||||||||||||||||||||
0x00DF | uint8_t InitialNode | |||||||||||||||||||||||||||||||||||
0x00E0 | void * ServiceTable | struct _KWAIT_BLOCK[4] WaitBlock | 0x0140 | |||||||||||||||||||||||||||||||||
0x00E0 | uint8_t[20] WaitBlockFill8 | uint8_t[20] WaitBlockFill4 | uint8_t[20] WaitBlockFill8 | uint8_t[20] WaitBlockFill4 | uint8_t[20] WaitBlockFill8 | uint8_t[20] WaitBlockFill4 | uint8_t[20] WaitBlockFill8 | uint8_t[20] WaitBlockFill4 | uint8_t[20] WaitBlockFill8 | uint8_t[20] WaitBlockFill4 | 0x0140 | |||||||||||||||||||||||||
0x00E0 | uint8_t[44] WaitBlockFill9 | uint8_t[68] WaitBlockFill5 | uint8_t[44] WaitBlockFill9 | uint8_t[68] WaitBlockFill5 | uint8_t[44] WaitBlockFill9 | uint8_t[68] WaitBlockFill5 | uint8_t[44] WaitBlockFill9 | uint8_t[68] WaitBlockFill5 | uint8_t[44] WaitBlockFill9 | uint8_t[68] WaitBlockFill5 | 0x0140 | |||||||||||||||||||||||||
0x00E0 | uint8_t[68] WaitBlockFill10 | uint8_t[116] WaitBlockFill6 | uint8_t[68] WaitBlockFill10 | uint8_t[116] WaitBlockFill6 | uint8_t[68] WaitBlockFill10 | uint8_t[116] WaitBlockFill6 | uint8_t[68] WaitBlockFill10 | uint8_t[116] WaitBlockFill6 | uint8_t[68] WaitBlockFill10 | uint8_t[116] WaitBlockFill6 | 0x0140 | |||||||||||||||||||||||||
0x00E0 | uint8_t[88] WaitBlockFill11 | uint8_t[164] WaitBlockFill7 | uint8_t[88] WaitBlockFill11 | uint8_t[164] WaitBlockFill7 | uint8_t[88] WaitBlockFill11 | uint8_t[164] WaitBlockFill7 | uint8_t[88] WaitBlockFill11 | uint8_t[164] WaitBlockFill7 | uint8_t[88] WaitBlockFill11 | uint8_t[164] WaitBlockFill7 | 0x0140 | |||||||||||||||||||||||||
uint8_t[40] WaitBlockFill8 | uint8_t[40] WaitBlockFill8 | uint8_t[40] WaitBlockFill8 | uint8_t[40] WaitBlockFill8 | uint8_t[40] WaitBlockFill8 | 0x0140 | |||||||||||||||||||||||||||||||
uint8_t[88] WaitBlockFill9 | uint8_t[88] WaitBlockFill9 | uint8_t[88] WaitBlockFill9 | uint8_t[88] WaitBlockFill9 | uint8_t[88] WaitBlockFill9 | 0x0140 | |||||||||||||||||||||||||||||||
uint8_t[136] WaitBlockFill10 | uint8_t[136] WaitBlockFill10 | uint8_t[136] WaitBlockFill10 | uint8_t[136] WaitBlockFill10 | uint8_t[136] WaitBlockFill10 | 0x0140 | |||||||||||||||||||||||||||||||
uint8_t[176] WaitBlockFill11 | uint8_t[176] WaitBlockFill11 | uint8_t[176] WaitBlockFill11 | uint8_t[176] WaitBlockFill11 | uint8_t[176] WaitBlockFill11 | 0x0140 | |||||||||||||||||||||||||||||||
0x00E4 | struct _KQUEUE * Queue | |||||||||||||||||||||||||||||||||||
0x00E7 | char PreviousMode | 0x0153 | ||||||||||||||||||||||||||||||||||
0x00E8 | unsigned long ApcQueueLock | |||||||||||||||||||||||||||||||||||
0x00EC | struct _KTHREAD_COUNTERS * ThreadCounters | struct _KTHREAD_COUNTERS * ThreadCounters | 0x0160 | |||||||||||||||||||||||||||||||||
0x00EF | uint8_t ResourceIndex | 0x0183 | ||||||||||||||||||||||||||||||||||
0x00F0 | struct _KTIMER Timer | |||||||||||||||||||||||||||||||||||
0x00F4 | struct _KTHREAD_COUNTERS * ThreadCounters | 0x0168 | ||||||||||||||||||||||||||||||||||
0x00FF | uint8_t ResourceIndex | 0x0183 | ||||||||||||||||||||||||||||||||||
0x0100 | struct _LIST_ENTRY QueueListEntry | |||||||||||||||||||||||||||||||||||
0x0104 | struct _XSTATE_SAVE * XStateSave | struct _XSTATE_SAVE * XStateSave | 0x0190 | |||||||||||||||||||||||||||||||||
0x0107 | uint8_t LargeStack | 0x01B3 | ||||||||||||||||||||||||||||||||||
0x0108 | uint8_t ApcStateIndex | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _UMS_CONTROL_BLOCK * Ucb | struct _UMS_CONTROL_BLOCK * Ucb | struct _UMS_CONTROL_BLOCK * Ucb | 0x01B8 | ||||||||||||||||||||||||
0x0109 | uint8_t ApcQueueable | |||||||||||||||||||||||||||||||||||
0x010A | uint8_t Preempted | |||||||||||||||||||||||||||||||||||
0x010B | uint8_t ProcessReadyQueue | |||||||||||||||||||||||||||||||||||
0x010C | uint8_t KernelStackResident | struct _XSTATE_SAVE * XStateSave | 0x0198 | |||||||||||||||||||||||||||||||||
0x010D | char Saturation | |||||||||||||||||||||||||||||||||||
0x010E | uint8_t IdealProcessor | |||||||||||||||||||||||||||||||||||
0x010F | volatile uint8_t NextProcessor | |||||||||||||||||||||||||||||||||||
0x0110 | char BasePriority | struct _KTRAP_FRAME * TrapFrame | 0x01C8 | |||||||||||||||||||||||||||||||||
0x0111 | uint8_t Spare4 | |||||||||||||||||||||||||||||||||||
0x0112 | char PriorityDecrement | |||||||||||||||||||||||||||||||||||
0x0113 | char Quantum | |||||||||||||||||||||||||||||||||||
0x0114 | uint8_t SystemAffinityActive | void * CallbackStack | void * CallbackStack | void * CallbackStack | void * CallbackStack | void * CallbackStack | void * CallbackStack | void * CallbackStack | 0x01D0 | |||||||||||||||||||||||||||
0x0115 | char PreviousMode | |||||||||||||||||||||||||||||||||||
0x0116 | uint8_t ResourceIndex | |||||||||||||||||||||||||||||||||||
0x0117 | uint8_t DisableBoost | uint8_t LargeStack | 0x01B3 | |||||||||||||||||||||||||||||||||
0x0118 | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | 0x01B8 | |||||||||||||||||||||||||||||||||
0x0118 | struct _LIST_ENTRY QueueListEntry | unsigned long UserAffinity | void * ServiceTable | void * ServiceTable | void * ServiceTable | struct _LIST_ENTRY QueueListEntry | 0x01D8 | |||||||||||||||||||||||||||||
0x011C | void * volatile Win32Thread | void * volatile Win32Thread | 0x01C0 | |||||||||||||||||||||||||||||||||
0x011C | struct _KPROCESS * Process | uint8_t ApcStateIndex | uint8_t ApcStateIndex | uint8_t ApcStateIndex | uint8_t ApcStateIndex | uint8_t ApcStateIndex | 0x01D8 | |||||||||||||||||||||||||||||
0x011C | uint8_t ApcStateIndex | 0x01E4 | ||||||||||||||||||||||||||||||||||
0x011D | uint8_t IdealProcessor | uint8_t IdealProcessor | uint8_t IdealProcessor | uint8_t IdealProcessor | 0x01D9 | |||||||||||||||||||||||||||||||
0x011D | uint8_t IdealProcessor | uint8_t IdealProcessor | 0x01E5 | |||||||||||||||||||||||||||||||||
0x011E | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | 0x01DA | |||||||||||||||||||||||||||||||
0x011E | uint8_t Preempted | uint8_t Preempted | 0x01E6 | |||||||||||||||||||||||||||||||||
0x011F | uint8_t ProcessReadyQueue | uint8_t ProcessReadyQueue | uint8_t ProcessReadyQueue | uint8_t ProcessReadyQueue | 0x01DB | |||||||||||||||||||||||||||||||
0x011F | uint8_t ProcessReadyQueue | uint8_t ProcessReadyQueue | 0x01E7 | |||||||||||||||||||||||||||||||||
0x0120 | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | void * volatile Win32Thread | void * volatile Win32Thread | 0x01C8 | |||||||||||||||||||||||||
0x0120 | uint8_t KernelStackResident | uint8_t KernelStackResident | uint8_t KernelStackResident | uint8_t KernelStackResident | 0x01DC | |||||||||||||||||||||||||||||||
0x0120 | unsigned long SoftAffinity | unsigned long Affinity | uint8_t KernelStackResident | uint8_t KernelStackResident | struct _KTRAP_FRAME * TrapFrame | 0x01F4 | ||||||||||||||||||||||||||||||
0x0121 | char BasePriority | char BasePriority | char BasePriority | char BasePriority | 0x01DD | |||||||||||||||||||||||||||||||
0x0121 | char BasePriority | char BasePriority | 0x01F5 | |||||||||||||||||||||||||||||||||
0x0122 | char PriorityDecrement | char PriorityDecrement | char PriorityDecrement | char PriorityDecrement | 0x01DE | |||||||||||||||||||||||||||||||
0x0122 | char PriorityDecrement | char PriorityDecrement | 0x01F6 | |||||||||||||||||||||||||||||||||
0x0123 | char Saturation | char Saturation | char Saturation | char Saturation | char Saturation | 0x01DF | ||||||||||||||||||||||||||||||
0x0123 | char Saturation | 0x01F7 | ||||||||||||||||||||||||||||||||||
0x0124 | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | 0x01C8 | |||||||||||||||||||||||||
0x0124 | void * FirstArgument | void * FirstArgument | 0x01D0 | |||||||||||||||||||||||||||||||||
0x0124 | unsigned long Affinity | void * ServiceTable | unsigned long KernelLimit | uintptr_t UserAffinity | uintptr_t UserAffinity | uintptr_t UserAffinity | uintptr_t UserAffinity | uintptr_t UserAffinity | void * FirstArgument | void * volatile Win32Thread | 0x01E0 | |||||||||||||||||||||||||
0x0124 | uintptr_t UserAffinity | 0x01F8 | ||||||||||||||||||||||||||||||||||
0x0128 | unsigned long CallbackDepth | void * CallbackStack | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | struct _KTRAP_FRAME * TrapFrame | 0x01D8 | |||||||||||||||||||||||||||
0x0128 | uintptr_t CallbackDepth | uintptr_t CallbackDepth | 0x01D8 | |||||||||||||||||||||||||||||||||
0x0128 | uint8_t Preempted | struct _KAPC_STATE *[2] ApcStatePointer | void * Win32kTable | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | void * CallbackStack | struct _UMS_CONTROL_BLOCK * Ucb | 0x01E8 | |||||||||||||||||||||||||
0x0128 | struct _KPROCESS * Process | 0x0200 | ||||||||||||||||||||||||||||||||||
0x0129 | uint8_t ProcessReadyQueue | |||||||||||||||||||||||||||||||||||
0x012A | uint8_t KernelStackResident | |||||||||||||||||||||||||||||||||||
0x012B | uint8_t NextProcessor | |||||||||||||||||||||||||||||||||||
0x012C | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | void * FirstArgument | 0x01E0 | |||||||||||||||||||||||||||||
0x012C | unsigned long Win32kLimit | uintptr_t Affinity | uintptr_t Affinity | uintptr_t Affinity | uintptr_t Affinity | struct _KUMS_CONTEXT_HEADER * volatile Uch | struct _UMS_CONTROL_BLOCK * Ucb | struct _UMS_CONTROL_BLOCK * Ucb | struct _UMS_CONTROL_BLOCK * Ucb | struct _UMS_CONTROL_BLOCK * Ucb | struct _UMS_CONTROL_BLOCK * Ucb | 0x01F0 | ||||||||||||||||||||||||
0x012C | void * CallbackStack | unsigned long Affinity | uint64_t Affinity | volatile unsigned long Affinity | void * ServiceTable | 0x0208 | ||||||||||||||||||||||||||||||
0x0130 | void * Win32Thread | struct _KAPC_STATE SavedApcState | struct _KAPC_STATE *[2] ApcStatePointer | uint8_t ApcStateIndex | unsigned long WaitTime | unsigned long WaitTime | 0x01AC | |||||||||||||||||||||||||||||
0x0130 | uint8_t ApcStateIndex | uint8_t ApcStateIndex | 0x01E0 | |||||||||||||||||||||||||||||||||
0x0130 | void * CallbackStack | 0x01E8 | ||||||||||||||||||||||||||||||||||
0x0130 | uintptr_t CallbackDepth | uintptr_t CallbackDepth | uintptr_t CallbackDepth | uintptr_t CallbackDepth | uintptr_t CallbackDepth | uintptr_t CallbackDepth | 0x01E8 | |||||||||||||||||||||||||||||
0x0130 | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | void * TebMappedLowVa | struct _KUMS_CONTEXT_HEADER * volatile Uch | struct _KUMS_CONTEXT_HEADER * volatile Uch | struct _KUMS_CONTEXT_HEADER * volatile Uch | struct _KUMS_CONTEXT_HEADER * volatile Uch | struct _KUMS_CONTEXT_HEADER * volatile Uch | 0x01F8 | |||||||||||||||||||||||||
0x0130 | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | 0x0210 | |||||||||||||||||||||||||||||||||
0x0131 | char BasePriority | 0x01E1 | ||||||||||||||||||||||||||||||||||
0x0132 | char PriorityDecrement | 0x01E2 | ||||||||||||||||||||||||||||||||||
0x0133 | uint8_t Preempted | 0x01E3 | ||||||||||||||||||||||||||||||||||
0x0134 | int16_t KernelApcDisable | 0x01DC | ||||||||||||||||||||||||||||||||||
0x0134 | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | 0x01DC | |||||||||||||||||||||||||||||||||
0x0134 | struct _KTRAP_FRAME * TrapFrame | uint8_t AdjustReason | uint8_t AdjustReason | int16_t KernelApcDisable | int16_t KernelApcDisable | 0x01E4 | ||||||||||||||||||||||||||||||
0x0134 | uint8_t ApcStateIndex | 0x01F0 | ||||||||||||||||||||||||||||||||||
0x0135 | char AdjustIncrement | char AdjustIncrement | 0x01E5 | |||||||||||||||||||||||||||||||||
0x0135 | char BasePriority | 0x01F1 | ||||||||||||||||||||||||||||||||||
0x0136 | uint8_t Spare01 | int16_t SpecialApcDisable | int16_t SpecialApcDisable | 0x01DE | ||||||||||||||||||||||||||||||||
0x0136 | uint8_t Spare01 | uint8_t Spare01 | 0x01E6 | |||||||||||||||||||||||||||||||||
0x0136 | char PriorityDecrement | 0x01F2 | ||||||||||||||||||||||||||||||||||
0x0136:0x00 | uint8_t ForegroundBoost | 0x01F2:0x00 | ||||||||||||||||||||||||||||||||||
0x0136:0x04 | uint8_t UnusualBoost | 0x01F2:0x04 | ||||||||||||||||||||||||||||||||||
0x0137 | char Saturation | char Saturation | 0x01E7 | |||||||||||||||||||||||||||||||||
0x0137 | uint8_t Preempted | 0x01F3 | ||||||||||||||||||||||||||||||||||
0x0138 | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE SavedApcState | unsigned long SystemCallNumber | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | unsigned long WaitTime | 0x01B4 | ||||||||||||||||||||||
0x0138 | unsigned long SystemCallNumber | unsigned long SystemCallNumber | 0x01E8 | |||||||||||||||||||||||||||||||||
0x0138 | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | 0x01F4 | |||||||||||||||||||||||||||||
0x0138 | uint8_t[23] SavedApcStateFill | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | 0x0200 | ||||||||||||||||||||||||||||||||
0x0138 | struct _KAPC_STATE SavedApcState | 0x0208 | ||||||||||||||||||||||||||||||||||
0x0138 | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | 0x0208 | |||||||||||||||||||||||||||||||
0x0138 | struct _KAPC_STATE SavedApcState | 0x0220 | ||||||||||||||||||||||||||||||||||
0x0138 | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | 0x0220 | |||||||||||||||||||||||||||||||||
0x0139 | char AdjustIncrement | 0x01F5 | ||||||||||||||||||||||||||||||||||
0x013A | char PreviousMode | 0x01F6 | ||||||||||||||||||||||||||||||||||
0x013B | char Saturation | 0x01F7 | ||||||||||||||||||||||||||||||||||
0x013C | int16_t KernelApcDisable | unsigned long CombinedApcDisable | int16_t KernelApcDisable | unsigned long CombinedApcDisable | int16_t KernelApcDisable | 0x01E4 | ||||||||||||||||||||||||||||||
0x013C | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | unsigned long CombinedApcDisable | 0x01E4 | |||||||||||||||||||||||||
0x013C | unsigned long Spare02 | unsigned long FreezeCount | unsigned long FreezeCount | int16_t KernelApcDisable | 0x01EC | |||||||||||||||||||||||||||||||
0x013C | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long SystemCallNumber | unsigned long CombinedApcDisable | 0x01F8 | ||||||||||||||||||||||||||||
0x013E | int16_t SpecialApcDisable | 0x01E6 | ||||||||||||||||||||||||||||||||||
0x0140 | uintptr_t UserAffinity | uintptr_t UserAffinity | 0x01F0 | |||||||||||||||||||||||||||||||||
0x0140 | unsigned long FreezeCount | unsigned long FreezeCount | unsigned long FreezeCount | unsigned long FreezeCount | unsigned long FreezeCount | unsigned long FreezeCount | 0x01FC | |||||||||||||||||||||||||||||
0x0140 | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | 0x0208 | |||||||||||||||||||||||||
0x0140 | char PreviousMode | unsigned long UserAffinity | volatile unsigned long NextProcessor | struct _LIST_ENTRY QueueListEntry | 0x0210 | |||||||||||||||||||||||||||||||
0x0141 | uint8_t EnableStackSwap | |||||||||||||||||||||||||||||||||||
0x0142 | uint8_t LargeStack | |||||||||||||||||||||||||||||||||||
0x0143 | uint8_t ResourceIndex | |||||||||||||||||||||||||||||||||||
0x0144 | struct _KPROCESS * Process | struct _KPROCESS * Process | 0x01F8 | |||||||||||||||||||||||||||||||||
0x0144 | volatile struct _GROUP_AFFINITY UserAffinity | volatile struct _GROUP_AFFINITY UserAffinity | volatile struct _GROUP_AFFINITY UserAffinity | volatile struct _GROUP_AFFINITY UserAffinity | volatile struct _GROUP_AFFINITY UserAffinity | volatile struct _GROUP_AFFINITY UserAffinity | 0x0200 | |||||||||||||||||||||||||||||
0x0144 | unsigned long KernelTime | struct _KPROCESS * Process | volatile unsigned long DeferredProcessor | 0x0214 | ||||||||||||||||||||||||||||||||
0x0148 | unsigned long UserTime | void * CallbackStack | volatile unsigned long Affinity | volatile uint64_t Affinity | void * TebMappedLowVa | void * TebMappedLowVa | void * TebMappedLowVa | volatile unsigned long NextProcessor | void * TebMappedLowVa | void * TebMappedLowVa | 0x0200 | |||||||||||||||||||||||||
0x0148 | struct _KPROCESS * Process | volatile unsigned long NextProcessor | volatile unsigned long NextProcessor | unsigned long NextProcessorNumber | volatile unsigned long NextProcessor | 0x0218 | ||||||||||||||||||||||||||||||
0x0148:0x00 | unsigned long NextProcessorNumber | unsigned long NextProcessorNumber | 0x0218:0x00 | |||||||||||||||||||||||||||||||||
0x0148:0x1F | unsigned long SharedReadyQueue | 0x0218:0x1F | ||||||||||||||||||||||||||||||||||
0x014C | struct _KAPC_STATE SavedApcState | void * Win32Thread | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _LIST_ENTRY QueueListEntry | struct _LIST_ENTRY QueueListEntry | long QueuePriority | 0x0208 | ||||||||||||||||||||||||||||
0x014C | volatile unsigned long DeferredProcessor | volatile unsigned long DeferredProcessor | long QueuePriority | long QueuePriority | long QueuePriority | long QueuePriority | long QueuePriority | long QueuePriority | long QueuePriority | long QueuePriority | long QueuePriority | 0x021C | ||||||||||||||||||||||||
0x014C | volatile struct _GROUP_AFFINITY UserAffinity | 0x0220 | ||||||||||||||||||||||||||||||||||
0x014C | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | 0x0220 | |||||||||||||||||||||||||||||||||
0x014F | char FreezeCount | char BasePriority | char BasePriority | 0x0233 | ||||||||||||||||||||||||||||||||
uint8_t CodePatchInProgress | 0x0247 | |||||||||||||||||||||||||||||||||||
0x014F | char FreezeCount | 0x024B | ||||||||||||||||||||||||||||||||||
0x0150 | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | 0x0210 | |||||||||||||||||||||||||||||
0x0150 | struct _KTRAP_FRAME * TrapFrame | char SuspendCount | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | struct _KPROCESS * Process | 0x0220 | |||||||||||||||||||||||
0x0150 | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | char PriorityDecrement | char PriorityDecrement | 0x0234 | |||||||||||||||||||||||||||||
0x0150 | char SuspendCount | 0x024C | ||||||||||||||||||||||||||||||||||
0x0151 | uint8_t UserIdealProcessor | uint8_t UserIdealProcessor | uint8_t UserIdealProcessor | uint8_t UserIdealProcessor | 0x0235 | |||||||||||||||||||||||||||||||
0x0151 | uint8_t UserIdealProcessor | uint8_t UserIdealProcessor | 0x024D | |||||||||||||||||||||||||||||||||
0x0152 | char PreviousMode | char PreviousMode | 0x022A | |||||||||||||||||||||||||||||||||
0x0152 | uint8_t CalloutActive | uint8_t CalloutActive | uint8_t CalloutActive | uint8_t CalloutActive | 0x0236 | |||||||||||||||||||||||||||||||
0x0152 | uint8_t CalloutActive | uint8_t CalloutActive | 0x024E | |||||||||||||||||||||||||||||||||
0x0153 | uint8_t Iopl | uint8_t Iopl | uint8_t Iopl | uint8_t Iopl | char BasePriority | 0x022B | ||||||||||||||||||||||||||||||
0x0154 | struct _KAPC_STATE SavedApcState | volatile struct _GROUP_AFFINITY Affinity | volatile struct _GROUP_AFFINITY Affinity | volatile struct _GROUP_AFFINITY Affinity | volatile struct _GROUP_AFFINITY Affinity | volatile struct _GROUP_AFFINITY Affinity | volatile struct _GROUP_AFFINITY Affinity | volatile unsigned long NextProcessor | volatile unsigned long NextProcessor | 0x0218 | ||||||||||||||||||||||||||
0x0154 | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | unsigned long NextProcessorNumber | unsigned long NextProcessorNumber | 0x0218 | ||||||||||||||||||||||||||||||||
0x0154 | unsigned long KernelTime | void * Win32Thread | struct _KAPC_STATE SavedApcState | volatile struct _GROUP_AFFINITY UserAffinity | uint8_t[10] UserAffinityFill | struct _GROUP_AFFINITY UserAffinity | uint8_t[10] UserAffinityFill | struct _GROUP_AFFINITY UserAffinity | 0x0228 | |||||||||||||||||||||||||||
0x0154 | uint8_t[23] SavedApcStateFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | x86: uint8_t[6] / x64: uint8_t[10] UserAffinityFill | 0x0228 | ||||||||||||||||||||||||
0x0154 | char PriorityDecrement | 0x022C | ||||||||||||||||||||||||||||||||||
0x0154:0x00 | uint8_t ForegroundBoost | uint8_t ForegroundBoost | 0x022C:0x00 | |||||||||||||||||||||||||||||||||
0x0154 | void * Win32Thread | 0x0238 | ||||||||||||||||||||||||||||||||||
uint8_t CodePatchInProgress | 0x024F | |||||||||||||||||||||||||||||||||||
0x0154 | void * Win32Thread | void * Win32Thread | 0x0250 | |||||||||||||||||||||||||||||||||
0x0154:0x04 | uint8_t UnusualBoost | 0x022C:0x04 | ||||||||||||||||||||||||||||||||||
0x0155 | uint8_t Preempted | 0x022D | ||||||||||||||||||||||||||||||||||
0x0156 | uint8_t AdjustReason | 0x022E | ||||||||||||||||||||||||||||||||||
0x0157 | char AdjustIncrement | 0x022F | ||||||||||||||||||||||||||||||||||
0x0158 | volatile struct _GROUP_AFFINITY Affinity | 0x0230 | ||||||||||||||||||||||||||||||||||
0x0158 | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | 0x0230 | |||||||||||||||||||||||||||||||||
0x0158 | void * StackBase | void * StackBase | void * StackBase | void * StackBase | 0x0240 | |||||||||||||||||||||||||||||||
0x0158 | unsigned long UserTime | void * StackBase | void * StackBase | void * StackBase | 0x0258 | |||||||||||||||||||||||||||||||
0x015A | char PreviousMode | 0x0232 | ||||||||||||||||||||||||||||||||||
0x015B | char BasePriority | char BasePriority | char BasePriority | 0x0233 | ||||||||||||||||||||||||||||||||
0x015C | char PriorityDecrement | uint8_t ForegroundBoost | char PriorityDecrement | uint8_t ForegroundBoost | char PriorityDecrement | 0x0234 | ||||||||||||||||||||||||||||||
0x015C:0x00 | uint8_t ForegroundBoost | uint8_t ForegroundBoost | uint8_t ForegroundBoost | uint8_t ForegroundBoost | uint8_t ForegroundBoost | uint8_t ForegroundBoost | uint8_t ForegroundBoost | uint8_t ForegroundBoost | uint8_t ForegroundBoost | uint8_t ForegroundBoost | 0x0234:0x00 | |||||||||||||||||||||||||
0x015C | struct _KAPC SuspendApc | 0x0248 | ||||||||||||||||||||||||||||||||||
0x015C | uint8_t[1] SuspendApcFill0 | 0x0248 | ||||||||||||||||||||||||||||||||||
0x015C | uint8_t[3] SuspendApcFill1 | 0x0248 | ||||||||||||||||||||||||||||||||||
0x015C | uint8_t[4] SuspendApcFill2 | 0x0248 | ||||||||||||||||||||||||||||||||||
0x015C | x86: uint8_t[36] / x64: uint8_t[64] SuspendApcFill3 | 0x0248 | ||||||||||||||||||||||||||||||||||
0x015C | x86: uint8_t[40] / x64: uint8_t[72] SuspendApcFill4 | 0x0248 | ||||||||||||||||||||||||||||||||||
0x015C | x86: uint8_t[47] / x64: uint8_t[83] SuspendApcFill5 | x86: uint8_t[47] / x64: uint8_t[83] SuspendApcFill5 | x86: uint8_t[47] / x64: uint8_t[83] SuspendApcFill5 | x86: uint8_t[47] / x64: uint8_t[83] SuspendApcFill5 | 0x0248 | |||||||||||||||||||||||||||||||
0x015C | void * StackBase | struct _KAPC SuspendApc | struct _KAPC SuspendApc | char PriorityDecrement | 0x0260 | |||||||||||||||||||||||||||||||
0x015C | uint8_t[1] SuspendApcFill0 | uint8_t[1] SuspendApcFill0 | uint8_t ForegroundBoost | 0x0260 | ||||||||||||||||||||||||||||||||
0x015C | uint8_t[3] SuspendApcFill1 | uint8_t[3] SuspendApcFill1 | 0x0260 | |||||||||||||||||||||||||||||||||
0x015C | uint8_t[4] SuspendApcFill2 | uint8_t[4] SuspendApcFill2 | 0x0260 | |||||||||||||||||||||||||||||||||
0x015C | x86: uint8_t[36] / x64: uint8_t[64] SuspendApcFill3 | x86: uint8_t[36] / x64: uint8_t[64] SuspendApcFill3 | 0x0260 | |||||||||||||||||||||||||||||||||
0x015C | x86: uint8_t[40] / x64: uint8_t[72] SuspendApcFill4 | x86: uint8_t[40] / x64: uint8_t[72] SuspendApcFill4 | 0x0260 | |||||||||||||||||||||||||||||||||
0x015C | x86: uint8_t[47] / x64: uint8_t[83] SuspendApcFill5 | x86: uint8_t[47] / x64: uint8_t[83] SuspendApcFill5 | x86: uint8_t[47] / x64: uint8_t[83] SuspendApcFill5 | 0x0260 | ||||||||||||||||||||||||||||||||
0x015C:0x04 | uint8_t UnusualBoost | 0x0234:0x04 | ||||||||||||||||||||||||||||||||||
0x015D | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | uint8_t Preempted | 0x0235 | |||||||||||||||||||||||||
0x015D | char Quantum | char Quantum | char Quantum | char Quantum | 0x0249 | |||||||||||||||||||||||||||||||
0x015D | char Quantum | char Quantum | uint8_t Preempted | 0x0261 | ||||||||||||||||||||||||||||||||
0x015E | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | uint8_t AdjustReason | 0x0236 | |||||||||||||||||||||||||
0x015E | uint8_t ApcStateIndex | uint8_t AdjustReason | 0x023A | |||||||||||||||||||||||||||||||||
0x015F | uint8_t CodePatchInProgress | uint8_t CodePatchInProgress | char AdjustIncrement | char AdjustIncrement | char AdjustIncrement | char AdjustIncrement | char AdjustIncrement | char AdjustIncrement | char AdjustIncrement | char AdjustIncrement | char AdjustIncrement | char AdjustIncrement | 0x0237 | |||||||||||||||||||||||
0x015F | uint8_t WaitBlockCount | uint8_t WaitBlockCount | 0x023B | |||||||||||||||||||||||||||||||||
0x015F | uint8_t QuantumReset | uint8_t QuantumReset | uint8_t QuantumReset | uint8_t QuantumReset | uint8_t QuantumReset | char AdjustIncrement | 0x024B | |||||||||||||||||||||||||||||
0x015F | uint8_t QuantumReset | 0x0263 | ||||||||||||||||||||||||||||||||||
0x0160 | struct _KAPC SuspendApc | unsigned long KernelTime | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | struct _GROUP_AFFINITY UserAffinity | struct _GROUP_AFFINITY UserAffinity | struct _GROUP_AFFINITY Affinity | 0x0228 | ||||||||||||||||||||||||
0x0160 | volatile struct _GROUP_AFFINITY Affinity | struct _GROUP_AFFINITY Affinity | struct _GROUP_AFFINITY Affinity | uintptr_t AffinityVersion | uintptr_t AffinityVersion | 0x0238 | ||||||||||||||||||||||||||||||
0x0160 | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | 0x0238 | |||||||||||||||||||||||||||
0x0160 | unsigned long IdealProcessor | unsigned long IdealProcessor | 0x023C | |||||||||||||||||||||||||||||||||
0x0160 | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | uint8_t[6] AffinityFill | 0x024C | ||||||||||||||||||||||||||||||
0x0160 | unsigned long KernelTime | 0x0264 | ||||||||||||||||||||||||||||||||||
0x0164 | unsigned long UserIdealProcessor | unsigned long UserIdealProcessor | unsigned long UserIdealProcessor | unsigned long UserIdealProcessor | unsigned long UserIdealProcessor | unsigned long UserIdealProcessor | 0x022C | |||||||||||||||||||||||||||||
0x0164 | uint8_t Alertable | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _GROUP_AFFINITY Affinity | 0x0240 | |||||||||||||||||||||||||||||||
0x0164 | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | x86: uint8_t[6] / x64: uint8_t[10] AffinityFill | 0x0240 | |||||||||||||||||||||||||||||||||
0x0165 | uint8_t ApcStateIndex | |||||||||||||||||||||||||||||||||||
0x0166 | uint8_t ApcQueueable | uint8_t ApcStateIndex | 0x0242 | |||||||||||||||||||||||||||||||||
0x0167 | uint8_t AutoAlignment | uint8_t WaitBlockCount | uint8_t WaitBlockCount | uint8_t WaitBlockCount | 0x0243 | |||||||||||||||||||||||||||||||
0x0168 | void * StackBase | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | unsigned long IdealProcessor | 0x0230 | |||||||||||||||||||||||||||
0x0168 | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | unsigned long IdealProcessor | 0x0244 | |||||||||||||||||||||||||||
0x016A | uint8_t ApcStateIndex | 0x024A | ||||||||||||||||||||||||||||||||||
0x016B | uint8_t Spare02 | uint8_t Spare02 | uint8_t WaitBlockCount | uint8_t WaitBlockCount | 0x0243 | |||||||||||||||||||||||||||||||
0x016B | char FreezeCount | uint8_t WaitBlockCount | 0x024B | |||||||||||||||||||||||||||||||||
0x016C | struct _KAPC SuspendApc | char SuspendCount | char SuspendCount | unsigned long IdealProcessor | unsigned long IdealProcessor | struct _KAPC_STATE *[2] ApcStatePointer | 0x0244 | |||||||||||||||||||||||||||||
0x016C | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | struct _KAPC_STATE *[2] ApcStatePointer | 0x0248 | |||||||||||||||||||||||||||
0x016C | unsigned long IdealProcessor | unsigned long IdealProcessor | 0x024C | |||||||||||||||||||||||||||||||||
0x016C | struct _KAPC_STATE SavedApcState | 0x0250 | ||||||||||||||||||||||||||||||||||
0x016C | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | 0x0250 | |||||||||||||||||||||||||||||||||
0x016D | uint8_t UserIdealProcessor | 0x0245 | ||||||||||||||||||||||||||||||||||
0x016E | uint8_t Spare03 | 0x0246 | ||||||||||||||||||||||||||||||||||
0x016F | uint8_t Iopl | uint8_t OtherPlatformFill | ||||||||||||||||||||||||||||||||||
0x0170 | struct _KAPC_STATE SavedApcState | 0x0240 | ||||||||||||||||||||||||||||||||||
0x0170 | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | 0x0240 | ||||||||||||||||||||||||||||||||||
0x0170 | void * volatile Win32Thread | unsigned long[1] Spare15 | 0x0248 | |||||||||||||||||||||||||||||||||
0x0174 | void * StackBase | void * StackBase | struct _KAPC_STATE SavedApcState | 0x0250 | ||||||||||||||||||||||||||||||||
0x0174 | struct _KAPC_STATE SavedApcState | struct _KAPC_STATE SavedApcState | uint8_t[23] SavedApcStateFill | struct _KAPC_STATE SavedApcState | 0x0258 | |||||||||||||||||||||||||||||||
0x0174 | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | x86: uint8_t[23] / x64: uint8_t[43] SavedApcStateFill | 0x0258 | |||||||||||||||||||||||||
0x0178 | struct _KAPC SuspendApc | struct _KAPC_STATE SavedApcState | struct _KAPC_STATE SavedApcState | 0x0258 | ||||||||||||||||||||||||||||||||
0x0178 | uint8_t[1] SuspendApcFill0 | uint8_t[43] SavedApcStateFill | uint8_t[43] SavedApcStateFill | 0x0258 | ||||||||||||||||||||||||||||||||
0x0178 | uint8_t[3] SuspendApcFill1 | 0x0258 | ||||||||||||||||||||||||||||||||||
0x0178 | uint8_t[4] SuspendApcFill2 | 0x0258 | ||||||||||||||||||||||||||||||||||
0x0178 | x86: uint8_t[36] / x64: uint8_t[64] SuspendApcFill3 | 0x0258 | ||||||||||||||||||||||||||||||||||
0x0178 | x86: uint8_t[40] / x64: uint8_t[72] SuspendApcFill4 | 0x0258 | ||||||||||||||||||||||||||||||||||
0x0178 | x86: uint8_t[47] / x64: uint8_t[83] SuspendApcFill5 | 0x0258 | ||||||||||||||||||||||||||||||||||
0x0179 | char Spare04 | 0x0259 | ||||||||||||||||||||||||||||||||||
0x017B | uint8_t QuantumReset | 0x025B | ||||||||||||||||||||||||||||||||||
0x017C | unsigned long KernelTime | 0x025C | ||||||||||||||||||||||||||||||||||
uint8_t CodePatchInProgress | uint8_t CodePatchInProgress | uint8_t CodePatchInProgress | 0x026E | |||||||||||||||||||||||||||||||||
0x0180 | void * TlsArray | void * TlsArray | void * TlsArray | void * TlsArray | void * TlsArray | struct _KAPC SchedulerApc | struct _KAPC SchedulerApc | 0x0288 | ||||||||||||||||||||||||||||
0x0180 | void * TlsArray | void * TlsArray | 0x02A0 | |||||||||||||||||||||||||||||||||
0x0183 | uint8_t WaitReason | 0x027B | ||||||||||||||||||||||||||||||||||
0x0184 | void * LegoData | char SuspendCount | char SuspendCount | 0x027C | ||||||||||||||||||||||||||||||||
0x0184 | void * LegoData | void * LegoData | void * LegoData | void * LegoData | 0x0290 | |||||||||||||||||||||||||||||||
0x0184 | void * LegoData | void * LegoData | 0x02A8 | |||||||||||||||||||||||||||||||||
0x0185 | char Saturation | 0x027D | ||||||||||||||||||||||||||||||||||
0x0186 | uint16_t SListFaultCount | uint16_t SListFaultCount | 0x027E | |||||||||||||||||||||||||||||||||
0x0187 | uint8_t WaitReason | 0x026B | ||||||||||||||||||||||||||||||||||
0x0188 | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | 0x026C | |||||||||||||||||||||||||||||
0x0188 | struct _KAPC SchedulerApc | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0188 | uint8_t[1] SchedulerApcFill0 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0188 | uint8_t[3] SchedulerApcFill1 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0188 | uint8_t[4] SchedulerApcFill2 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0188 | x86: uint8_t[36] / x64: uint8_t[64] SchedulerApcFill3 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0188 | x86: uint8_t[40] / x64: uint8_t[72] SchedulerApcFill4 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0188 | x86: uint8_t[47] / x64: uint8_t[83] SchedulerApcFill5 | x86: uint8_t[47] / x64: uint8_t[83] SchedulerApcFill5 | 0x0280 | |||||||||||||||||||||||||||||||||
0x0189 | char Spare1 | char Spare1 | char Spare1 | char Spare1 | char Spare1 | char Spare1 | 0x026D | |||||||||||||||||||||||||||||
0x0189 | uint8_t ResourceIndex | 0x0281 | ||||||||||||||||||||||||||||||||||
0x018A | uint8_t OtherPlatformFill | uint8_t OtherPlatformFill | uint8_t OtherPlatformFill | |||||||||||||||||||||||||||||||||
0x018B | uint8_t PowerState | uint8_t QuantumReset | uint8_t QuantumReset | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | uint8_t WaitReason | 0x0283 | ||||||||||||||||||||||
0x018B | uint8_t PowerState | uint8_t PowerState | uint8_t PowerState | uint8_t PowerState | 0x029B | |||||||||||||||||||||||||||||||
0x018B | uint8_t PowerState | 0x02B3 | ||||||||||||||||||||||||||||||||||
0x018C | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | void * volatile Win32Thread | 0x0270 | |||||||||||||||||||||||||||||
0x018C | unsigned long UserTime | unsigned long KernelTime | unsigned long KernelTime | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | char SuspendCount | 0x0284 | ||||||||||||||||||||||
0x018C | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | 0x029C | |||||||||||||||||||||||||||||||
0x018C | unsigned long UserTime | unsigned long UserTime | 0x02B4 | |||||||||||||||||||||||||||||||||
0x018D | char Saturation | 0x0285 | ||||||||||||||||||||||||||||||||||
0x018E | uint16_t SListFaultCount | 0x0286 | ||||||||||||||||||||||||||||||||||
0x0190 | struct _KSEMAPHORE SuspendSemaphore | struct _KSEMAPHORE SuspendSemaphore | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | void * StackBase | struct _KAPC SchedulerApc | 0x0278 | ||||||||||||||||||||||||||
0x0190 | struct _KAPC SchedulerApc | uint8_t[1] SchedulerApcFill0 | struct _KAPC SchedulerApc | uint8_t[1] SchedulerApcFill0 | uint8_t[4] SchedulerApcFill2 | struct _KAPC SchedulerApc | 0x0288 | |||||||||||||||||||||||||||||
0x0190 | uint8_t[1] SchedulerApcFill0 | uint8_t[3] SchedulerApcFill1 | uint8_t[1] SchedulerApcFill0 | uint8_t[3] SchedulerApcFill1 | uint8_t[36] SchedulerApcFill3 | uint8_t[1] SchedulerApcFill0 | 0x0288 | |||||||||||||||||||||||||||||
0x0190 | uint8_t[3] SchedulerApcFill1 | uint8_t[4] SchedulerApcFill2 | uint8_t[3] SchedulerApcFill1 | uint8_t[4] SchedulerApcFill2 | uint8_t[40] SchedulerApcFill4 | uint8_t[3] SchedulerApcFill1 | 0x0288 | |||||||||||||||||||||||||||||
0x0190 | uint8_t[4] SchedulerApcFill2 | uint8_t[64] SchedulerApcFill3 | uint8_t[4] SchedulerApcFill2 | uint8_t[64] SchedulerApcFill3 | uint8_t[47] SchedulerApcFill5 | uint8_t[4] SchedulerApcFill2 | 0x0288 | |||||||||||||||||||||||||||||
0x0190 | x86: uint8_t[36] / x64: uint8_t[64] SchedulerApcFill3 | uint8_t[72] SchedulerApcFill4 | x86: uint8_t[36] / x64: uint8_t[64] SchedulerApcFill3 | uint8_t[72] SchedulerApcFill4 | x86: uint8_t[36] / x64: uint8_t[64] SchedulerApcFill3 | 0x0288 | ||||||||||||||||||||||||||||||
0x0190 | x86: uint8_t[40] / x64: uint8_t[72] SchedulerApcFill4 | uint8_t[83] SchedulerApcFill5 | x86: uint8_t[40] / x64: uint8_t[72] SchedulerApcFill4 | uint8_t[83] SchedulerApcFill5 | x86: uint8_t[40] / x64: uint8_t[72] SchedulerApcFill4 | 0x0288 | ||||||||||||||||||||||||||||||
0x0190 | x86: uint8_t[47] / x64: uint8_t[83] SchedulerApcFill5 | x86: uint8_t[47] / x64: uint8_t[83] SchedulerApcFill5 | x86: uint8_t[47] / x64: uint8_t[83] SchedulerApcFill5 | 0x0288 | ||||||||||||||||||||||||||||||||
0x0190 | struct _KSEMAPHORE SuspendSemaphore | uint8_t[20] SuspendSemaphorefill | uint8_t[1] SchedulerApcFill0 | 0x02A0 | ||||||||||||||||||||||||||||||||
0x0190 | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | uint8_t[3] SchedulerApcFill1 | 0x02A0 | ||||||||||||||||||||||||||||||
0x0190 | struct _KSEMAPHORE SuspendSemaphore | 0x02B8 | ||||||||||||||||||||||||||||||||||
0x0190 | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | 0x02B8 | |||||||||||||||||||||||||||||||||
0x0191 | uint8_t ResourceIndex | 0x0289 | ||||||||||||||||||||||||||||||||||
0x0193 | uint8_t QuantumReset | 0x028B | ||||||||||||||||||||||||||||||||||
0x0194 | struct _KAPC SuspendApc | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0194 | uint8_t[1] SuspendApcFill0 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0194 | uint8_t[3] SuspendApcFill1 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0194 | uint8_t[4] SuspendApcFill2 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0194 | x86: uint8_t[36] / x64: uint8_t[64] SuspendApcFill3 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0194 | x86: uint8_t[40] / x64: uint8_t[72] SuspendApcFill4 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0194 | x86: uint8_t[47] / x64: uint8_t[83] SuspendApcFill5 | 0x0280 | ||||||||||||||||||||||||||||||||||
0x0194 | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | unsigned long KernelTime | 0x028C | |||||||||||||||||||||||||
0x0195 | uint8_t ResourceIndex | 0x0281 | ||||||||||||||||||||||||||||||||||
0x0197 | uint8_t QuantumReset | 0x0283 | ||||||||||||||||||||||||||||||||||
0x0198 | unsigned long KernelTime | 0x0284 | ||||||||||||||||||||||||||||||||||
0x019C | struct _KSEMAPHORE SuspendSemaphore | struct _KPRCB * WaitPrcb | 0x0298 | |||||||||||||||||||||||||||||||||
0x01A0 | void * LegoData | 0x02A0 | ||||||||||||||||||||||||||||||||||
0x01A4 | void * TlsArray | unsigned long SListFaultCount | unsigned long SListFaultCount | unsigned long SListFaultCount | unsigned long SListFaultCount | unsigned long SListFaultCount | 0x02BC | |||||||||||||||||||||||||||||
0x01A4 | unsigned long SListFaultCount | unsigned long SListFaultCount | 0x02D4 | |||||||||||||||||||||||||||||||||
0x01A7 | uint8_t PowerState | 0x02AB | ||||||||||||||||||||||||||||||||||
0x01A8 | unsigned long UserTime | unsigned long UserTime | 0x02AC | |||||||||||||||||||||||||||||||||
0x01A8 | void * LegoData | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | unsigned long UserTime | 0x02C0 | ||||||||||||||||||||||||||||
0x01A8 | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | 0x02D8 | |||||||||||||||||||||||||||||||||
0x01AC | struct _LIST_ENTRY ThreadListEntry | struct _KSEMAPHORE SuspendSemaphore | 0x02B0 | |||||||||||||||||||||||||||||||||
0x01AC | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | 0x02B0 | |||||||||||||||||||||||||||||||||
0x01AC | struct _KPRCB * volatile WaitPrcb | 0x02C0 | ||||||||||||||||||||||||||||||||||
0x01B0 | void * LegoData | void * LegoData | 0x02C8 | |||||||||||||||||||||||||||||||||
0x01B0 | struct _LIST_ENTRY ThreadListEntry | void * SListFaultAddress | void * SListFaultAddress | void * SListFaultAddress | void * SListFaultAddress | void * SListFaultAddress | void * LegoData | void * LegoData | 0x02D0 | |||||||||||||||||||||||||||
0x01B0 | void * SListFaultAddress | int64_t OtherOperationCount | int64_t OtherOperationCount | 0x02E8 | ||||||||||||||||||||||||||||||||
0x01B4 | uint8_t LargeStack | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | 0x02C8 | ||||||||||||||||||||||||
0x01B5 | uint8_t PowerState | |||||||||||||||||||||||||||||||||||
0x01B6 | uint8_t NpxIrql | |||||||||||||||||||||||||||||||||||
0x01B7 | uint8_t Spare5 | uint8_t CallbackNestingLevel | 0x02D3 | |||||||||||||||||||||||||||||||||
0x01B8 | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | struct _KPRCB * volatile WaitPrcb | 0x02C0 | |||||||||||||||||||||||||||||
0x01B8 | char FreezeCount | uint8_t AutoAlignment | void * LegoData | void * LegoData | void * LegoData | 0x02D0 | ||||||||||||||||||||||||||||||
0x01B8 | unsigned long UserTime | 0x02D4 | ||||||||||||||||||||||||||||||||||
0x01B9 | char SuspendCount | uint8_t Iopl | ||||||||||||||||||||||||||||||||||
0x01BA | uint8_t IdealProcessor | char FreezeCount | ||||||||||||||||||||||||||||||||||
0x01BB | uint8_t DisableBoost | char SuspendCount | ||||||||||||||||||||||||||||||||||
0x01BC | void * LegoData | void * LegoData | void * LegoData | void * LegoData | void * LegoData | void * LegoData | 0x02C8 | |||||||||||||||||||||||||||||
0x01BC | uint8_t[1] Spare0 | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | 0x02D8 | ||||||||||||||||||||||||||||||||
0x01BD | uint8_t UserIdealProcessor | |||||||||||||||||||||||||||||||||||
0x01BE | volatile uint8_t DeferredProcessor | |||||||||||||||||||||||||||||||||||
0x01BF | uint8_t AdjustReason | uint8_t CallbackNestingLevel | 0x02DB | |||||||||||||||||||||||||||||||||
0x01C0 | char AdjustIncrement | unsigned long SListFaultCount | unsigned long SListFaultCount | unsigned long UserTime | 0x02CC | |||||||||||||||||||||||||||||||
0x01C0 | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | 0x02DC | |||||||||||||||||||||||||
0x01C1 | uint8_t[3] Spare2 | |||||||||||||||||||||||||||||||||||
0x01C3 | uint8_t LargeStack | 0x02D3 | ||||||||||||||||||||||||||||||||||
0x01C4 | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | struct _KEVENT SuspendEvent | 0x02D0 | ||||||||||||||||||||||||||||||||
0x01C4 | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | unsigned long UserTime | 0x02D4 | |||||||||||||||||||||||||||||
0x01C4 | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | 0x02E0 | |||||||||||||||||||||||||
0x01C8 | int64_t ReadOperationCount | int64_t ReadOperationCount | struct _KSEMAPHORE SuspendSemaphore | 0x02D8 | ||||||||||||||||||||||||||||||||
0x01C8 | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | x86: uint8_t[20] / x64: uint8_t[28] SuspendSemaphorefill | 0x02D8 | |||||||||||||||||||||||||||||
0x01CC | int64_t WriteOperationCount | int64_t WriteOperationCount | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _KEVENT SuspendEvent | struct _KEVENT SuspendEvent | 0x02E0 | |||||||||||||||||||||||||||||
0x01CC | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | 0x02F0 | |||||||||||||||||||||||||||||||||
0x01D4 | int64_t ReadOperationCount | int64_t ReadTransferCount | int64_t ReadTransferCount | void * SListFaultAddress | void * SListFaultAddress | struct _LIST_ENTRY ThreadListEntry | 0x02F0 | |||||||||||||||||||||||||||||
0x01D4 | int64_t WriteOperationCount | int64_t WriteTransferCount | int64_t WriteTransferCount | int64_t ReadOperationCount | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | 0x02F8 | |||||||||||||||||||||||||||||
0x01D4 | int64_t OtherOperationCount | int64_t OtherTransferCount | int64_t OtherTransferCount | int64_t WriteOperationCount | struct _LIST_ENTRY MutantListHead | 0x0300 | ||||||||||||||||||||||||||||||
int64_t WriteTransferCount | int64_t ReadTransferCount | int64_t ReadOperationCount | 0x0310 | |||||||||||||||||||||||||||||||||
unsigned long SecureThreadCookie | unsigned long SecureThreadCookie | unsigned long SecureThreadCookie | 0x031C | |||||||||||||||||||||||||||||||||
0x01D8 | void * volatile MdlForLockedTeb | int64_t WriteOperationCount | int64_t WriteOperationCount | int64_t WriteOperationCount | int64_t ReadTransferCount | int64_t OtherOperationCount | 0x0328 | |||||||||||||||||||||||||||||
0x01DC | unsigned long SListFaultCount | unsigned long SListFaultCount | unsigned long SListFaultCount | unsigned long SListFaultCount | unsigned long SListFaultCount | unsigned long SListFaultCount | 0x02F4 | |||||||||||||||||||||||||||||
0x01DC | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | 0x0308 | |||||||||||||||||||||||||
0x01E0 | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | struct _LIST_ENTRY ThreadListEntry | 0x02F8 | |||||||||||||||||||||||||||||
0x01E4 | int64_t OtherTransferCount | int64_t WriteTransferCount | int64_t WriteOperationCount | int64_t ReadOperationCount | struct _SINGLE_LIST_ENTRY LockEntriesFreeList | uint8_t AbEntrySummary | 0x0318 | |||||||||||||||||||||||||||||
0x01E5 | uint8_t AbWaitEntryCount | 0x0319 | ||||||||||||||||||||||||||||||||||
0x01E6 | uint16_t Spare20 | 0x031A | ||||||||||||||||||||||||||||||||||
0x01E8 | int64_t ReadTransferCount | int64_t OtherOperationCount | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _LIST_ENTRY MutantListHead | struct _KLOCK_ENTRY[6] LockEntries | 0x0308 | ||||||||||||||||||||||||
0x01E8 | int64_t OtherTransferCount | int64_t ReadOperationCount | int64_t ReadOperationCount | int64_t ReadOperationCount | int64_t OtherOperationCount | int64_t WriteOperationCount | struct _KLOCK_ENTRY[5] LockEntries | struct _KLOCK_ENTRY[6] LockEntries | struct _KLOCK_ENTRY[6] LockEntries | struct _KLOCK_ENTRY[6] LockEntries | struct _KLOCK_ENTRY[6] LockEntries | struct _KLOCK_ENTRY[6] LockEntries | struct _KLOCK_ENTRY[6] LockEntries | struct _KLOCK_ENTRY[6] LockEntries | struct _KLOCK_ENTRY[6] LockEntries | 0x0320 | ||||||||||||||||||||
0x01F0 | void * SListFaultAddress | 0x0318 | ||||||||||||||||||||||||||||||||||
int64_t OtherOperationCount | int64_t OtherOperationCount | int64_t OtherOperationCount | int64_t WriteTransferCount | int64_t ReadTransferCount | 0x0330 | |||||||||||||||||||||||||||||||
int64_t ReadTransferCount | int64_t ReadTransferCount | int64_t ReadTransferCount | int64_t OtherTransferCount | int64_t WriteTransferCount | 0x0338 | |||||||||||||||||||||||||||||||
int64_t WriteTransferCount | int64_t WriteTransferCount | int64_t WriteTransferCount | int64_t OtherTransferCount | 0x0340 | ||||||||||||||||||||||||||||||||
int64_t OtherTransferCount | int64_t OtherTransferCount | int64_t OtherTransferCount | 0x0348 | |||||||||||||||||||||||||||||||||
0x01F4 | struct _KTHREAD_COUNTERS * ThreadCounters | 0x0350 | ||||||||||||||||||||||||||||||||||
0x01F8 | struct _XSTATE_SAVE * XStateSave | struct _XSTATE_SAVE * XStateSave | struct _XSTATE_SAVE * XStateSave | struct _XSTATE_SAVE * XStateSave | struct _XSAVE_FORMAT * StateSaveArea | 0x0358 | ||||||||||||||||||||||||||||||
0x01F8 | struct _XSTATE_SAVE * XStateSave | 0x0360 | ||||||||||||||||||||||||||||||||||
struct _SINGLE_LIST_ENTRY PropagateBoostsEntry | 0x0500 | |||||||||||||||||||||||||||||||||||
struct _SINGLE_LIST_ENTRY IoSelfBoostsEntry | 0x0508 | |||||||||||||||||||||||||||||||||||
uint8_t[16] PriorityFloorCounts | 0x0510 | |||||||||||||||||||||||||||||||||||
unsigned long PriorityFloorSummary | 0x0520 | |||||||||||||||||||||||||||||||||||
volatile long AbCompletedIoBoostCount | 0x0524 | |||||||||||||||||||||||||||||||||||
volatile int16_t AbReferenceCount | 0x0528 | |||||||||||||||||||||||||||||||||||
uint8_t AbFreeEntryCount | 0x052A | |||||||||||||||||||||||||||||||||||
uint8_t AbWaitEntryCount | 0x052B | |||||||||||||||||||||||||||||||||||
unsigned long ForegroundLossTime | 0x052C | |||||||||||||||||||||||||||||||||||
struct _LIST_ENTRY GlobalForegroundListEntry | 0x0530 | |||||||||||||||||||||||||||||||||||
struct _SINGLE_LIST_ENTRY ForegroundDpcStackListEntry | 0x0530 | |||||||||||||||||||||||||||||||||||
uint64_t InGlobalForegroundList | 0x0538 | |||||||||||||||||||||||||||||||||||
uint16_t[20] Padding | 0x0540 | |||||||||||||||||||||||||||||||||||
0x0308 | struct _SINGLE_LIST_ENTRY PropagateBoostsEntry | 0x0560 | ||||||||||||||||||||||||||||||||||
0x030C | int64_t ReadOperationCount | struct _SINGLE_LIST_ENTRY IoSelfBoostsEntry | 0x0568 | |||||||||||||||||||||||||||||||||
0x0310 | int64_t WriteOperationCount | uint8_t[16] PriorityFloorCounts | uint8_t[16] PriorityFloorCounts | uint8_t[16] PriorityFloorCounts | uint8_t[16] PriorityFloorCounts | uint8_t[16] PriorityFloorCounts | uint8_t[16] PriorityFloorCounts | uint8_t[16] PriorityFloorCounts | uint8_t[16] PriorityFloorCounts | 0x0570 | ||||||||||||||||||||||||||
int64_t OtherOperationCount | 0x0578 | |||||||||||||||||||||||||||||||||||
0x0320 | int64_t ReadTransferCount | unsigned long PriorityFloorSummary | 0x0580 | |||||||||||||||||||||||||||||||||
0x0324 | volatile long AbCompletedIoBoostCount | 0x0584 | ||||||||||||||||||||||||||||||||||
0x0328 | int64_t WriteTransferCount | volatile int16_t AbReferenceCount | volatile int16_t KeReferenceCount | 0x0588 | ||||||||||||||||||||||||||||||||
0x032A | uint8_t AbFreeEntryCount | uint8_t AbOrphanedEntrySummary | 0x058A | |||||||||||||||||||||||||||||||||
0x032B | uint8_t AbWaitEntryCount | uint8_t AbOwnedEntryCount | 0x058B | |||||||||||||||||||||||||||||||||
0x032C | unsigned long ForegroundLossTime | 0x058C | ||||||||||||||||||||||||||||||||||
0x0330 | int64_t OtherTransferCount | struct _LIST_ENTRY GlobalForegroundListEntry | 0x0590 | |||||||||||||||||||||||||||||||||
0x0330 | struct _SINGLE_LIST_ENTRY ForegroundDpcStackListEntry | 0x0590 | ||||||||||||||||||||||||||||||||||
0x0334 | uintptr_t InGlobalForegroundList | 0x0598 | ||||||||||||||||||||||||||||||||||
int64_t ReadOperationCount | int64_t ReadOperationCount | int64_t ReadOperationCount | int64_t ReadOperationCount | 0x05A0 | ||||||||||||||||||||||||||||||||
int64_t WriteOperationCount | int64_t WriteOperationCount | int64_t WriteOperationCount | int64_t WriteOperationCount | 0x05A8 | ||||||||||||||||||||||||||||||||
int64_t OtherOperationCount | int64_t OtherOperationCount | int64_t OtherOperationCount | int64_t OtherOperationCount | 0x05B0 | ||||||||||||||||||||||||||||||||
int64_t ReadTransferCount | int64_t ReadTransferCount | int64_t ReadTransferCount | int64_t ReadTransferCount | 0x05B8 | ||||||||||||||||||||||||||||||||
int64_t WriteTransferCount | int64_t WriteTransferCount | int64_t WriteTransferCount | int64_t WriteTransferCount | 0x05C0 | ||||||||||||||||||||||||||||||||
int64_t OtherTransferCount | int64_t OtherTransferCount | int64_t OtherTransferCount | int64_t OtherTransferCount | 0x05C8 | ||||||||||||||||||||||||||||||||
0x0338 | struct _KSCB * QueuedScb | 0x05D0 | ||||||||||||||||||||||||||||||||||
0x0340 | uint64_t NpxState | 0x0250 |