|
Wireshark 4.7.0
The Wireshark network protocol analyzer
|
Pseudo-header for Microsoft ProcMon (Process Monitor) captures. More...
#include <wtap.h>
Public Attributes | |
| uint32_t * | process_index_map |
| size_t | process_index_map_size |
| struct procmon_process_t * | process_array |
| size_t | process_array_size |
| bool | system_bitness |
Pseudo-header for Microsoft ProcMon (Process Monitor) captures.
| struct procmon_process_t* procmon_phdr::process_array |
Array of captured process descriptors.
| size_t procmon_phdr::process_array_size |
Number of entries in process_array.
| uint32_t* procmon_phdr::process_index_map |
Map from raw process index to process_array index.
| size_t procmon_phdr::process_index_map_size |
Number of entries in process_index_map.
| bool procmon_phdr::system_bitness |
True if the captured system was 64-bit, false if 32-bit.