Index

A B C D E F G H I K L M N O P Q R S T U V W _ 
All Classes and Interfaces|All Packages|Constant Field Values|Serialized Form

G

getBarInfo() - Method in interface leechcore.ILeechCore
Retrieve info about the 6 PCIe BARs.
getCmdLine() - Method in interface vmm.IVmmProcess
Get the process command line.
getConfig(long) - Method in interface vmm.IVmm
Get a device specific option value.
getCountEAT() - Method in interface vmm.IVmmModule
Retrieve the export address table (EAT) count.
getCountIAT() - Method in interface vmm.IVmmModule
Retrieve the import address table (IAT) count.
getCountSection() - Method in interface vmm.IVmmModule
Retrieve the module section count.
getDTB() - Method in interface vmm.IVmmProcess
Get the kernel directory table base (default).
getDTBUser() - Method in interface vmm.IVmmProcess
Get the user mode directory table base (if exists).
getEPROCESS() - Method in interface vmm.IVmmProcess
Retrieve the virtual address of the EPROCESS struct.
getExDebugInfo() - Method in interface vmm.IVmmModule
Retrieve debug directory information.
getExVersionInfo() - Method in interface vmm.IVmmModule
Retrieve PE version info.
getFlags() - Method in interface vmm.IVmmMemScatterMemory
Retrieve the flags.
getKeyChild() - Method in interface vmm.IVmmRegKey
Retrieve the child keys.
getKeyOrphan() - Method in interface vmm.IVmmRegHive
Retrieve the virtual registry hive orphan key.
getKeyParent() - Method in interface vmm.IVmmRegKey
Retrieve the parent key.
getKeyParent() - Method in interface vmm.IVmmRegValue
Retrieve the parent key.
getKeyRoot() - Method in interface vmm.IVmmRegHive
Retrieve the registry hive root key.
GetLUID() - Method in interface vmm.IVmmProcess
Get the LUID from the process token.
getMemMap() - Method in interface leechcore.ILeechCore
Retrieve the memory map in use by LeechCore.
getModuleName() - Method in interface vmm.IVmmPdb
Retrieve the module name of the PDB debug symbols.
getName() - Method in interface vmm.IVmmModule
Retrieve the module name.
getName() - Method in interface vmm.IVmmProcess
Get the short process name.
getName() - Method in interface vmm.IVmmRegHive
Retrieve the registry hive full name.
getName() - Method in interface vmm.IVmmRegKey
Retrieve the registry key name.
getName() - Method in interface vmm.IVmmRegValue
Retrieve the registry key name.
getNameFull() - Method in interface vmm.IVmmModule
Retrieve the full/long module name.
getNameFull() - Method in interface vmm.IVmmProcess
Get the full process name.
getNameShort() - Method in interface vmm.IVmmRegHive
Retrieve the registry hive short name.
getNativeLibraryPath() - Method in interface leechcore.ILeechCore
Retrieve the native library path set at initialization time.
getNativeLibraryPath() - Method in interface vmm.IVmm
Retrieve the native library path set at initialization time.
getOption(long) - Method in interface leechcore.ILeechCore
Get a device specific option value.
getPath() - Method in interface vmm.IVmmRegHive
Retrieve the registry hive path.
getPath() - Method in interface vmm.IVmmRegKey
Retrieve the registry key path.
getPath() - Method in interface vmm.IVmmRegValue
Retrieve the registry key path.
getPathKernel() - Method in interface vmm.IVmmProcess
Get the kernel mode process path.
getPathUser() - Method in interface vmm.IVmmProcess
Get the user mode process path.
getPdb() - Method in interface vmm.IVmmModule
Retrieve pdb debug symbols for the specific module.
getPEB() - Method in interface vmm.IVmmProcess
Get the virtual address of the PEB.
getPEB32() - Method in interface vmm.IVmmProcess
Get the virtual address of the 32-bit PEB in WoW64 processes.
getPID() - Method in interface vmm.IVmmProcess
Retrieve the PID of this process object.
getPPID() - Method in interface vmm.IVmmProcess
Retrieve the parent process id (PPID).
getProcAddress(String) - Method in interface vmm.IVmmModule
Retrieve the function address of the specified function.
getProcess() - Method in interface vmm.IVmmModule
Retrieve the process object of this module object.
GetSessionID() - Method in interface vmm.IVmmProcess
Get the SesssionID from the process token.
getSID() - Method in interface vmm.IVmmProcess
Get the SID from the process token.
getSize() - Method in interface vmm.IVmmModule
Retrieve the size of the module (in virtual memory).
getSize() - Method in interface vmm.IVmmRegHive
Retrieve the registry hive size.
getSizeFile() - Method in interface vmm.IVmmModule
Retrieve the file size (raw size) of the module.
getState() - Method in interface vmm.IVmmProcess
Get the process state.
getSymbolAddress(String) - Method in interface vmm.IVmmPdb
Retrieve the address of the given symbol.
getSymbolName(long) - Method in interface vmm.IVmmPdb
Retrieve the symbol name given symbol virtual address or offset.
getTime() - Method in interface vmm.IVmmRegKey
Retrieve the last write time.
getTpMemoryModel() - Method in interface vmm.IVmmProcess
Get the memory model.
getTpSystem() - Method in interface vmm.IVmmProcess
Get the system type.
getType() - Method in interface vmm.IVmmRegValue
Retrieve the registry type.
getTypeChildOffset(String, String) - Method in interface vmm.IVmmPdb
Retrieve the symbol type child offset.
getTypeSize(String) - Method in interface vmm.IVmmPdb
Retrieve a type size.
getVaBase() - Method in interface vmm.IVmmModule
Retrieve the module base address.
getVaBaseBlock() - Method in interface vmm.IVmmRegHive
Retrieve the address of the registry base block.
getVaEntry() - Method in interface vmm.IVmmModule
Retieve the module entry point address.
getVaHive() - Method in interface vmm.IVmmRegHive
Retrieve the base address of the registry hive.
getValue() - Method in interface vmm.IVmmRegValue
Retrieve the raw registry value.
getValueAsDword() - Method in interface vmm.IVmmRegValue
Retrieve a DWORD value.
getValueAsString() - Method in interface vmm.IVmmRegValue
Retrieve the registry value as a String.
getValues() - Method in interface vmm.IVmmRegKey
Retrieve the values.
Guid - Variable in class vmm.entry.Vmm_ModuleExDebugInfo
 
GuidBytes - Variable in class vmm.entry.Vmm_ModuleExDebugInfo
 
A B C D E F G H I K L M N O P Q R S T U V W _ 
All Classes and Interfaces|All Packages|Constant Field Values|Serialized Form