2. The windows
objects¶
Through the system object many classes representing various Windows parts are accessible.
This sections describes them by group of relation.
- 2.1. Processes and Threads
- 2.2. PEB Exploration
- 2.3. PEFile - Parsing loaded PE
- 2.4. Token
- 2.5. Exception and Context related structures
- 2.6. Registry
- 2.7. Network
- 2.8. Service
- 2.9. Volume – The logical drives
- 2.10. WMI – Make request to WMI
- 2.11. Handle – Processes handles
- 2.12. System Module – Loaded kernel modules
- 2.13. Object Manager – Kernel objects
- 2.14. Device Manager
- 2.15. Task scheduler
- 2.16. Event Log
- 2.17. ETW – Event Tracing for Windows