Skip to content

Instantly share code, notes, and snippets.

View AndreyBazhan's full-sized avatar

Andrey Bazhan AndreyBazhan

View GitHub Profile
@AndreyBazhan
AndreyBazhan / ws.cpp
Created May 27, 2019 19:49
Process Explorer: Process Properties->Performance tab performance issue
#include <Windows.h>
#include <psapi.h>
int main()
{
HANDLE ProcessHandle;
ULONG Processes[4096];
ULONG DataSize;
ULONG NumberOfProcesses;
@AndreyBazhan
AndreyBazhan / gist:0c12ea4c83833f756b9afbfa6bb66cdd
Created April 30, 2019 15:06
List of Windows kernels that have incorrect offsets in MiState _MI_SYSTEM_INFORMATION structure
?? @@(ntoskrnl!MiState) + #FIELD_OFFSET(ntoskrnl!_MI_SYSTEM_INFORMATION, Vs); ? poi(ntoskrnl!MiVisibleState)
10.0.15063.1659 x64
unsigned int64 0x00000001`4036d080
Evaluate expression: 5372301504 = 00000001`4036d0c0
10.0.15063.1659 x86
unsigned int64 0x60f700