wtap_open_return_val procmon_open(wtap *wth, int *err, char **err_info)
Opens a procmon file and initializes the wtap structure.
Definition procmon.c:436
Describes a single loaded module (DLL or executable image) within a monitored process.
Definition procmon.h:17
const char * image_path
Definition procmon.h:21
uint64_t base_address
Definition procmon.h:19
const char * company
Definition procmon.h:23
uint32_t size
Definition procmon.h:20
const char * description
Definition procmon.h:24
const char * version
Definition procmon.h:22
nstime_t timestamp
Definition procmon.h:18
Describes a single process observed by Process Monitor, including its identity, security context,...
Definition procmon.h:30
const char * command_line
Definition procmon.h:42
const char * version
Definition procmon.h:44
bool is_64_bit
Definition procmon.h:49
uint32_t process_id
Definition procmon.h:34
const char * company
Definition procmon.h:43
procmon_module_t * modules
Definition procmon.h:46
const char * description
Definition procmon.h:45
bool is_virtualized
Definition procmon.h:48
uint64_t authentication_id
Definition procmon.h:33
uint32_t num_modules
Definition procmon.h:47
nstime_t end_time
Definition procmon.h:32
const char * user_name
Definition procmon.h:39
const char * image_path
Definition procmon.h:41
const char * process_name
Definition procmon.h:40
uint32_t session_number
Definition procmon.h:37
uint32_t parent_process_index
Definition procmon.h:36
const char * integrity
Definition procmon.h:38
nstime_t start_time
Definition procmon.h:31
uint32_t parent_process_id
Definition procmon.h:35
Definition wtap_module.h:58
wtap_open_return_val
For registering file types that we can open.
Definition wtap.h:1849