📄 ntoskrnl.def
字号:
@KeAcquireInStackQueuedSpinLockAtDpcLevel@8
KeAcquireInterruptSpinLock@4
;KeAcquireSpinLockAtDpcLevel
KeAddSystemServiceTable@20
KeAreApcsDisabled@0
KeAttachProcess@4
KeBugCheck@4
KeBugCheckEx@20
KeCancelTimer@4
KeClearEvent@4
;KeConnectInterrupt
;KeDcacheFlushCount DATA
KeDelayExecutionThread@12
KeDeregisterBugCheckCallback@4
KeDetachProcess@0
;KeDisconnectInterrupt
KeEnterCriticalRegion@0
;KeEnterKernelDebugger
;KeFindConfigurationEntry
;KeFindConfigurationNextEntry
;KeFlushEntireTb
KeGetCurrentThread@0
KeGetPreviousMode@0
KeGetRecommendedSharedDataAlignment@0
;KeI386AbiosCall
;KeI386AllocateGdtSelectors
;KeI386Call16BitCStyleFunction
;KeI386Call16BitFunction
;KeI386FlatToGdtSelector
;KeI386GetLid
;KeI386MachineType DATA
;KeI386ReleaseGdtSelectors
;KeI386ReleaseLid
;KeI386SetGdtSelector
;KeIcacheFlushCount DATA
KeInitializeApc@32
KeInitializeDeviceQueue@4
KeInitializeDpc@12
KeInitializeEvent@12
;KeInitializeInterrupt
;KeInitializeMutant
KeInitializeMutex@8
;KeInitializeQueue
KeInitializeSemaphore@12
KeInitializeSpinLock@4
KeInitializeTimer@4
KeInitializeTimerEx@8
KeInsertByKeyDeviceQueue@12
KeInsertDeviceQueue@8
;KeInsertHeadQueue
;KeInsertQueue
;KeInsertQueueApc
KeInsertQueueDpc@12
;KeIsAttachedProcess
;KeIsExecutingDpc
KeLeaveCriticalRegion@0
;KeLoaderBlock DATA
;KeNumberProcessors DATA
;KeProfileInterrupt
;KeProfileInterruptWithSource
KePulseEvent@12
;KeQueryActiveProcessors
KeQueryInterruptTime@0
KeQueryPriorityThread@4
;KeQueryRuntimeThread
KeQuerySystemTime@4
KeQueryTickCount@4
KeQueryTimeIncrement@0
;KeRaiseUserException
KeReadStateEvent@4
;KeReadStateMutant
KeReadStateMutex@4
;KeReadStateQueue
KeReadStateSemaphore@4
KeReadStateTimer@4
KeRegisterBugCheckCallback@20
KeReleaseInStackQueuedSpinLockFromDpcLevel@4
KeReleaseInterruptSpinLock@8
;KeReleaseMutant
KeReleaseMutex@8
KeReleaseSemaphore@16
;KeReleaseSpinLockFromDpcLevel
KeRemoveByKeyDeviceQueue@8
;KeRemoveByKeyDeviceQueueIfBusy
KeRemoveDeviceQueue@4
KeRemoveEntryDeviceQueue@8
;KeRemoveQueue
KeRemoveQueueDpc@4
;KeRemoveSystemServiceTable
KeResetEvent@4
KeRestoreFloatingPointState@4
;KeRevertToUserAffinityThread
;KeRundownQueue
KeSaveFloatingPointState@4
;KeSaveStateForHibernate
;KeServiceDescriptorTable DATA
;KeSetAffinityThread
KeSetBasePriorityThread@8
;KeSetDmaIoCoherency
KeSetEvent@12
;KeSetEventBoostPriority
;KeSetIdealProcessorThread
KeSetImportanceDpc@8
;KeSetKernelStackSwapEnable
KeSetPriorityThread@8
;KeSetProfileIrql
;KeSetSystemAffinityThread
KeSetTargetProcessorDpc@8
;KeSetTimeIncrement
@KeSetTimeUpdateNotifyRoutine@4
KeSetTimer@16
KeSetTimerEx@20
;KeStackAttachProcess
KeSynchronizeExecution@12
;KeTerminateThread
;KeTickCount DATA
;KeUnstackDetachProcess
;KeUpdateRunTime
;KeUpdateSystemTime
;KeUserModeCallback
KeWaitForMultipleObjects@32
KeWaitForMutexObject@20
KeWaitForSingleObject@20
@KefAcquireSpinLockAtDpcLevel@4
@KefReleaseSpinLockFromDpcLevel@4
;Kei386EoiHelper
;KiAcquireSpinLock
;KiBugCheckData DATA
;KiCoprocessorError
;KiDeliverApc
;KiDispatchInterrupt
;KiEnableTimerWatchdog DATA
;KiIpiServiceRoutine
;KiReleaseSpinLock
;KiUnexpectedInterrupt
;Kii386SpinOnSpinLock
;LdrAccessResource
;LdrEnumResources
;LdrFindResourceDirectory_U
;LdrFindResource_U
LpcPortObjectType DATA
;LpcRequestPort
;LpcRequestWaitReplyPort
;LsaCallAuthenticationPackage
;LsaDeregisterLogonProcess
;LsaFreeReturnBuffer
;LsaLogonUser
;LsaLookupAuthenticationPackage
;LsaRegisterLogonProcess
;Mm64BitPhysicalAddress DATA
;MmAddPhysicalMemory
;MmAddVerifierThunks
;MmAdjustWorkingSetSize
MmAdvanceMdl@8
MmAllocateContiguousMemory@8
MmAllocateContiguousMemorySpecifyCache@20
MmAllocateMappingAddress@8
MmAllocateNonCachedMemory@4
MmAllocatePagesForMdl@28
MmBuildMdlForNonPagedPool@4
;MmCanFileBeTruncated
MmCreateMdl@12
MmCreateSection@32
;MmDisableModifiedWriteOfSection
MmFlushImageSection@8
;MmForceSectionClosed
MmFreeContiguousMemory@4
MmFreeContiguousMemorySpecifyCache@12
MmFreeMappingAddress@8
MmFreeNonCachedMemory@8
MmFreePagesFromMdl@4
MmGetPhysicalAddress@4
MmGetPhysicalMemoryRanges@0
MmGetSystemRoutineAddress@4
MmGetVirtualForPhysical@4
;MmGrowKernelStack
;MmHighestUserAddress DATA
MmIsAddressValid@4
MmIsDriverVerifying@4
MmIsNonPagedSystemAddressValid@4
;MmIsRecursiveIoFault
MmIsThisAnNtAsSystem@0
MmIsVerifierEnabled@4
MmLockPagableDataSection@4
MmLockPagableImageSection@4
MmLockPagableSectionByHandle@4
MmMapIoSpace@16
MmMapLockedPages@8
MmMapLockedPagesSpecifyCache@24
MmMapLockedPagesWithReservedMapping@16
;MmMapMemoryDumpMdl
MmMapUserAddressesToPage@12
MmMapVideoDisplay@12
MmMapViewInSessionSpace@12
MmMapViewInSystemSpace@12
;MmMapViewOfSection
MmMarkPhysicalMemoryAsBad@8
MmMarkPhysicalMemoryAsGood@8
MmPageEntireDriver@4
;MmPrefetchPages
MmProbeAndLockPages@12
MmProbeAndLockProcessPages@16
;MmProbeAndLockSelectedPages
MmProtectMdlSystemAddress@8
MmQuerySystemSize@0
MmRemovePhysicalMemory@8
MmResetDriverPaging@4
MmSectionObjectType DATA
MmSecureVirtualMemory@12
;MmSetAddressRangeModified
;MmSetBankedSection
MmSizeOfMdl@8
;MmSystemRangeStart DATA
;MmTrimAllSystemPagableMemory
MmUnlockPagableImageSection@4
MmUnlockPages@4
MmUnmapIoSpace@8
MmUnmapLockedPages@8
MmUnmapReservedMapping@12
MmUnmapVideoDisplay@8
MmUnmapViewInSessionSpace@4
MmUnmapViewInSystemSpace@4
;MmUnmapViewOfSection
MmUnsecureVirtualMemory@4
;MmUserProbeAddress DATA
;NlsAnsiCodePage DATA
;NlsLeadByteInfo
;NlsMbCodePageTag DATA
;NlsMbOemCodePageTag DATA
;NlsOemCodePage DATA
;NlsOemLeadByteInfo
NtAddAtom@12
NtAdjustPrivilegesToken@24
NtAllocateLocallyUniqueId@4
NtAllocateUuids@16
NtAllocateVirtualMemory@24
;NtBuildNumber DATA
NtClose@4
NtConnectPort@32
NtCreateEvent@20
;NtCreateFile
NtCreateSection@28
NtDeleteAtom@4
NtDeleteFile@4
NtDeviceIoControlFile@40
NtDuplicateObject@28
NtDuplicateToken@24
NtFindAtom@12
NtFreeVirtualMemory@16
;NtFsControlFile
;NtGlobalFlag DATA
;NtLockFile
;NtMakePermanentObject
NtMapViewOfSection@40
;NtNotifyChangeDirectoryFile
NtOpenFile@24
NtOpenProcess@16
NtOpenProcessToken@12
;NtOpenProcessTokenEx
NtOpenThread@16
NtOpenThreadToken@16
;NtOpenThreadTokenEx
;NtQueryDirectoryFile
;NtQueryEaFile
NtQueryInformationAtom@20
;NtQueryInformationFile
NtQueryInformationProcess@20
NtQueryInformationThread@20
NtQueryInformationToken@20
;NtQueryQuotaInformationFile
NtQuerySecurityObject@20
NtQuerySystemInformation@16
;NtQueryVolumeInformationFile
NtReadFile@36
NtRequestPort@8
NtRequestWaitReplyPort@12
;NtSetEaFile
NtSetEvent@8
;NtSetInformationFile
NtSetInformationProcess@16
NtSetInformationThread@16
;NtSetQuotaInformationFile
NtSetSecurityObject@12
;NtSetVolumeInformationFile
NtShutdownSystem@4
;NtTraceEvent
;NtUnlockFile
NtVdmControl@8
NtWaitForSingleObject@12
NtWriteFile@36
ObAssignSecurity@16
;ObCheckCreateObjectAccess
;ObCheckObjectAccess
;ObCloseHandle
ObCreateObject@36
;ObCreateObjectType
;ObDereferenceObject
ObDereferenceSecurityDescriptor@8
;ObFindHandleForObject
ObGetObjectSecurity@12
ObInsertObject@24
ObLogSecurityDescriptor@12
ObMakeTemporaryObject@4
ObOpenObjectByName@28
ObOpenObjectByPointer@28
;ObQueryNameString
ObQueryObjectAuditingByHandle@8
ObReferenceObjectByHandle@24
ObReferenceObjectByName@32
ObReferenceObjectByPointer@16
ObReferenceSecurityDescriptor@8
ObReleaseObjectSecurity@8
;ObSetHandleAttributes
;ObSetSecurityDescriptorInfo
;ObSetSecurityObjectByPointer
@ObfDereferenceObject@4
@ObfReferenceObject@4
;PfxFindPrefix
;PfxInitialize
;PfxInsertPrefix
;PfxRemovePrefix
PoCallDriver@8
;PoCancelDeviceNotify
;PoQueueShutdownWorkItem
PoRegisterDeviceForIdleDetection@16
;PoRegisterDeviceNotify
PoRegisterSystemState@8
PoRequestPowerIrp@24
PoRequestShutdownEvent@4
;PoSetHiberRange
PoSetPowerState@12
PoSetSystemState@4
;PoShutdownBugCheck
PoStartNextPowerIrp@4
PoUnregisterSystemState@4
ProbeForRead@12
ProbeForWrite@12
;PsAssignImpersonationToken
;PsChargePoolQuota
;PsChargeProcessNonPagedPoolQuota
;PsChargeProcessPagedPoolQuota
;PsChargeProcessPoolQuota
PsCreateSystemProcess@12
PsCreateSystemThread@28
;PsDereferenceImpersonationToken
;PsDereferencePrimaryToken
;PsDisableImpersonation
;PsEstablishWin32Callouts
;PsGetCurrentProcess
PsGetCurrentProcessId@0
;PsGetCurrentProcessSessionId
;PsGetCurrentThread
PsGetCurrentThreadId@0
;PsGetCurrentThreadPreviousMode
;PsGetCurrentThreadStackBase
;PsGetCurrentThreadStackLimit
;PsGetJobLock
;PsGetJobSessionId
;PsGetJobUIRestrictionsClass
;PsGetProcessCreateTimeQuadPart
;PsGetProcessDebugPort
;PsGetProcessExitProcessCalled
;PsGetProcessExitStatus
;PsGetProcessExitTime
;PsGetProcessId
;PsGetProcessImageFileName
;PsGetProcessInheritedFromUniqueProcessId
;PsGetProcessJob
;PsGetProcessPeb
;PsGetProcessPriorityClass
;PsGetProcessSectionBaseAddress
;PsGetProcessSecurityPort
;PsGetProcessSessionId
;PsGetProcessWin32Process
;PsGetProcessWin32WindowStation
;PsGetThreadFreezeCount
;PsGetThreadHardErrorsAreDisabled
;PsGetThreadId
;PsGetThreadProcess
;PsGetThreadProcessId
;PsGetThreadSessionId
;PsGetThreadTeb
;PsGetThreadWin32Thread
PsGetVersion@16
;PsImpersonateClient
;PsInitialSystemProcess DATA
;PsIsProcessBeingDebugged
;PsIsSystemThread
;PsIsThreadImpersonating
;PsIsThreadTerminating
;PsJobType DATA
;PsLookupProcessByProcessId
;PsLookupProcessThreadByCid
;PsLookupThreadByThreadId
;PsProcessType DATA
;PsReferenceImpersonationToken
;PsReferencePrimaryToken
PsRemoveCreateThreadNotifyRoutine@4
PsRemoveLoadImageNotifyRoutine@4
;PsRestoreImpersonation
;PsReturnPoolQuota
;PsReturnProcessNonPagedPoolQuota
;PsReturnProcessPagedPoolQuota
;PsRevertThreadToSelf
;PsRevertToSelf
PsSetCreateProcessNotifyRoutine@8
PsSetCreateThreadNotifyRoutine@4
;PsSetJobUIRestrictionsClass
;PsSetLegoNotifyRoutine
PsSetLoadImageNotifyRoutine@4
;PsSetProcessPriorityByClass
;PsSetProcessPriorityClass
;PsSetProcessSecurityPort
;PsSetProcessWin32Process
;PsSetProcessWindowStation
;PsSetThreadHardErrorsAreDisabled
;PsSetThreadWin32Thread
PsTerminateSystemThread@4
;PsThreadType DATA
READ_REGISTER_BUFFER_UCHAR@12
READ_REGISTER_BUFFER_ULONG@12
READ_REGISTER_BUFFER_USHORT@12
READ_REGISTER_UCHAR@4
READ_REGISTER_ULONG@4
READ_REGISTER_USHORT@4
;RtlAbsoluteToSelfRelativeSD
;RtlAddAccessAllowedAce
;RtlAddAce
;RtlAddAtomToAtomTable
RtlAddRange@28
;RtlAllocateHeap
;RtlAnsiCharToUnicodeChar
RtlAnsiStringToUnicodeSize@4
RtlAnsiStringToUnicodeString@12
;RtlAppendAsciizToString
;RtlAppendStringToString
RtlAppendUnicodeStringToString@8
RtlAppendUnicodeToString@8
;RtlAreAllAccessesGranted
;RtlAreAnyAccessesGranted
RtlAreBitsClear@12
RtlAreBitsSet@12
RtlAssert@16
;RtlCaptureContext
;RtlCaptureStackBackTrace
RtlCharToInteger@12
RtlCheckRegistryKey@8
RtlClearAllBits@4
RtlClearBit@8
RtlClearBits@12
RtlCompareMemory@12
;RtlCompareMemoryUlong
RtlCompareString@12
RtlCompareUnicodeString@12
;RtlCompressBuffer
;RtlCompressChunks
RtlConvertLongToLargeInteger@4
;RtlConvertSidToUnicodeString
RtlConvertUlongToLargeInteger@4
;RtlCopyLuid
RtlCopyRangeList@8
;RtlCopySid
RtlCopyString@8
RtlCopyUnicodeString@8
;RtlCreateAcl
;RtlCreateAtomTable
;RtlCreateHeap
RtlCreateRegistryKey@8
RtlCreateSecurityDescriptor@8
;RtlCreateSystemVolumeInformationFolder
;RtlCreateUnicodeString
;RtlCustomCPToUnicodeN
;RtlDecompressBuffer
;RtlDecompressChunks
;RtlDecompressFragment
;RtlDelete
;RtlDeleteAce
;RtlDeleteAtomFromAtomTable
;RtlDeleteElementGenericTable
;RtlDeleteElementGenericTableAvl
;RtlDeleteNoSplay
RtlDeleteOwnersRanges@8
RtlDeleteRange@16
RtlDeleteRegistryValue@12
;RtlDescribeChunk
;RtlDestroyAtomTable
;RtlDestroyHeap
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -