MCPcopy Create free account
hub / github.com/ELMERIKH/PyinMemoryPE / enumerate_threads_setup_owners

Method enumerate_threads_setup_owners

windows/winobject/system.py:477–508  ·  view source on GitHub ↗
(self)

Source from the content-addressed store, hash-verified

475
476
477 def enumerate_threads_setup_owners(self):
478 # Enumerating threads is a special operation concerning the owner process.
479 # We may not be able to retrieve the name of the owning process by normal way
480 # (as we need to get a handle on the process)
481 # So, this implementation of enumerate_thread also setup the owner with the result of enumerate_processes
482 dbgprint("Enumerating threads with CreateToolhelp32Snapshot and setup owner", "SLOW")
483
484 # One snap for both enum to be prevent race
485 snap = winproxy.CreateToolhelp32Snapshot(gdef.TH32CS_SNAPTHREAD | gdef.TH32CS_SNAPPROCESS, 0)
486
487 process_entry = gdef.PROCESSENTRY32W()
488 process_entry.dwSize = ctypes.sizeof(process_entry)
489 winproxy.Process32FirstW(snap, process_entry)
490 processes = []
491 processes.append(process.WinProcess._from_PROCESSENTRY32(process_entry))
492 while winproxy.Process32NextW(snap, process_entry):
493 processes.append(process.WinProcess._from_PROCESSENTRY32(process_entry))
494
495 # Forge a dict pid -> process
496 proc_dict = {proc.pid: proc for proc in processes}
497
498 thread_entry = gdef.THREADENTRY32()
499 thread_entry.dwSize = ctypes.sizeof(thread_entry)
500 threads = []
501 winproxy.Thread32First(snap, thread_entry)
502 parent = proc_dict[thread_entry.th32OwnerProcessID]
503 threads.append(process.WinThread._from_THREADENTRY32(thread_entry, owner=parent))
504 while winproxy.Thread32Next(snap, thread_entry):
505 parent = proc_dict[thread_entry.th32OwnerProcessID]
506 threads.append(process.WinThread._from_THREADENTRY32(thread_entry, owner=parent))
507 winproxy.CloseHandle(snap)
508 return threads

Callers 1

threadsMethod · 0.95

Calls 3

_from_PROCESSENTRY32Method · 0.80
_from_THREADENTRY32Method · 0.80
sizeofMethod · 0.45

Tested by

no test coverage detected