Type a page name and press Enter. You'll jump to the page if it exists, or you can create it if it doesn't.
To create a page in a module other than ntdll, prefix the name with the module name and a period.
//helper method with "dynamic" buffer allocation
public static IntPtr NtQueryObject(IntPtr handle, OBJECT_INFORMATION_CLASS infoClass, uint infoLength = 0)
{
if (infoLength == 0)
infoLength = (uint)Marshal.SizeOf(typeof(uint));
IntPtr infoPtr = Marshal.AllocHGlobal((int)infoLength);
int tries = 0;
NtStatus result;
while (true)
{
result = NtQueryObject(handle, infoClass, infoPtr, infoLength, ref infoLength);
if (result == NtStatus.InfoLengthMismatch || result == NtStatus.BufferOverflow || result == NtStatus.BufferTooSmall)
{
Marshal.FreeHGlobal(infoPtr);
infoPtr = Marshal.AllocHGlobal((int)infoLength);
tries++;
continue;
}
else if (result == NtStatus.Success || tries > 5)
break;
else
{
//throw new Exception("Unhandled NtStatus " + result);
break;
}
}
if (result == NtStatus.Success)
return infoPtr;//don't forget to free the pointer with Marshal.FreeHGlobal after you're done with it
else
Marshal.FreeHGlobal(infoPtr);//free pointer when not Successful
return IntPtr.Zero;
}
Windows NT status codes
8/27/2018 4:52:25 AM - -71.231.140.159
Please edit this page!
Do you have...
helpful tips or sample code to share for using this API in managed code?
corrections to the existing content?
variations of the signature you want to share?
additional languages you want to include?
Select "Edit This Page" on the right hand toolbar and edit it! Or add new pages containing supporting types needed for this API (structures, delegates, and more).