Include NtQueryInformationProcess function and its associated structures like PROCESS_BASIC_INFORMATION/PEB/RTL_USER_PROCESS_PARAMETERS
See original GitHub issueIs your feature request related to a problem? Please describe. I would request that we include NtQueryInformationProcess into Vanara.PInvoke.NTDll, and also put the associated structures for the function in suitable locations.
On a side note, given a UNICODE_STRING
from the Vanara library, can I read its buffer contents from another process in an idiomatic way?
Issue Analytics
- State:
- Created 3 years ago
- Comments:21 (11 by maintainers)
Top Results From Across the Web
NtQueryInformationProcess function (winternl.h)
The NtQueryInformationProcess function and the structures that it returns are internal to the operating system and subject to change from one ...
Read more >NtQueryInformationProcess Undocumented Structs & PEB Ldr
You can find the NtQueryInformationProcess function exported by ... The modules are defined as LDR_DATA_TABLE_ENTRY and contain many useful ...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
Using the code available here (https://stackoverflow.com/a/16142791/1438337), I get the correct CommandLine.
I’ve noticed there is a difference between this code and your: there is an offset when reading PebBaseAddress and when getting UNICODE_STRING_WOW64 / RTL_USER_PROCESS_PARAMETERS (offseet with different values according to x32/x64): maybe that could be the issue ?
I would like, if possible, not having to do the P/Invoke import on my side and rely on your lib instead 😃