<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Exported NTDLL and kernel structures</title>
	<link>https://www.dumpanalysis.org/blog/index.php/2007/02/10/exported-ntdll-and-kernel-structures/</link>
	<description>Structural and Behavioral Patterns for Software Diagnostics, Forensics and Prognostics</description>
	<pubDate>Tue, 05 May 2026 17:51:10 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Dmitry Vostokov</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2007/02/10/exported-ntdll-and-kernel-structures/#comment-27733</link>
		<dc:creator>Dmitry Vostokov</dc:creator>
		<pubDate>Mon, 19 May 2008 13:36:33 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2007/02/10/exported-ntdll-and-kernel-structures/#comment-27733</guid>
		<description>If you mean the fact that wildcards don't work in 6.9.3.113 version of WinDbg then I haven't reported it yet.</description>
		<content:encoded><![CDATA[<p>If you mean the fact that wildcards don&#8217;t work in 6.9.3.113 version of WinDbg then I haven&#8217;t reported it yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2007/02/10/exported-ntdll-and-kernel-structures/#comment-27732</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Mon, 19 May 2008 13:22:30 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2007/02/10/exported-ntdll-and-kernel-structures/#comment-27732</guid>
		<description>Did you report this to Microsoft?</description>
		<content:encoded><![CDATA[<p>Did you report this to Microsoft?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nickdigital</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2007/02/10/exported-ntdll-and-kernel-structures/#comment-846</link>
		<dc:creator>nickdigital</dc:creator>
		<pubDate>Tue, 27 Mar 2007 22:37:13 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2007/02/10/exported-ntdll-and-kernel-structures/#comment-846</guid>
		<description>In case anyone is interested, the output from the above is 275 unique data types...
     PROCESSOR_IDLE_TIMES
     _CLIENT_ID
     _CM_PARTIAL_RESOURCE_LIST
     _CONTEXT
     _CURDIR
     _DESCRIPTOR
     _DISPATCHER_HEADER
     _ERESOURCE
     _EX_FAST_REF
     _EX_PUSH_LOCK
     _EX_RUNDOWN_REF
     _FAST_MUTEX
     _FLOATING_SAVE_AREA
     _FNSAVE_FORMAT
     _FS_FILTER_PARAMETERS
     _FXSAVE_FORMAT
     _FX_SAVE_AREA
     _GDI_TEB_BATCH
     _GENERAL_LOOKASIDE
     _GENERIC_MAPPING
     _HARDWARE_PTE_X86
     _HEAP_ENTRY
     _IMAGE_FILE_HEADER
     _IMAGE_OPTIONAL_HEADER
     _INITIAL_PRIVILEGE_SET
     _IO_COUNTERS
     _IO_STATUS_BLOCK
     _KAPC
     _KAPC_STATE
     _KDEVICE_QUEUE
     _KDEVICE_QUEUE_ENTRY
     _KDPC
     _KEVENT
     _KEXECUTE_OPTIONS
     _KGATE
     _KGDTENTRY
     _KGUARDED_MUTEX
     _KIDTENTRY
     _KPRCB
     _KPROCESS
     _KPROCESSOR_STATE
     _KSEMAPHORE
     _KSPECIAL_REGISTERS
     _KSYSTEM_TIME
     _KTHREAD
     _KTIMER
     _LARGE_INTEGER
     _LIST_ENTRY
     _LUID
     _MMADDRESS_NODE
     _MMSUPPORT
     _MMSUPPORT_FLAGS
     _MM_AVL_TABLE
     _NT_TIB
     _OBJECT_HANDLE_COUNT_ENTRY
     _OBJECT_TYPE_INITIALIZER
     _POWER_STATE
     _PRIVILEGE_SET
     _PROCESSOR_POWER_STATE
     _QUAD
     _RTL_AVL_TABLE
     _RTL_BALANCED_LINKS
     _RTL_CRITICAL_SECTION
     _SECURITY_QUALITY_OF_SERVICE
     _SECURITY_SUBJECT_CONTEXT
     _SE_AUDIT_PROCESS_CREATION_INFO
     _SID
     _SID_IDENTIFIER_AUTHORITY
     _SINGLE_LIST_ENTRY
     _SLIST_HEADER
     _STRING
     _ULARGE_INTEGER
     _UNICODE_STRING
     _WAIT_CONTEXT_BLOCK
     __unnamed
     _flags
 LIST_ENTRY32
 LIST_ENTRY64
 PROCESSOR_IDLE_TIMES
 PROCESSOR_PERF_STATE
 _ACCESS_STATE
 _ACTIVATION_CONTEXT
 _ACTIVATION_CONTEXT_DATA
 _ACTIVATION_CONTEXT_STACK
 _ASSEMBLY_STORAGE_MAP
 _CLIENT_ID
 _CM_FULL_RESOURCE_DESCRIPTOR
 _CM_PARTIAL_RESOURCE_DESCRIPTOR
 _CM_PARTIAL_RESOURCE_LIST
 _CM_RESOURCE_LIST
 _COMPRESSED_DATA_INFO
 _CONTEXT
 _CURDIR
 _DESCRIPTOR
 _DEVICE_CAPABILITIES
 _DEVICE_MAP
 _DEVICE_OBJECT
 _DEVICE_OBJECT_POWER_EXTENSION
 _DEVOBJ_EXTENSION
 _DISPATCHER_HEADER
 _DPH_BLOCK_INFORMATION
 _DPH_HEAP_BLOCK
 _DPH_HEAP_ROOT
 _DRIVER_EXTENSION
 _DRIVER_OBJECT
 _EJOB
 _EPROCESS
 _EPROCESS_QUOTA_BLOCK
 _EPROCESS_QUOTA_ENTRY
 _ERESOURCE
 _ETHREAD
 _EXCEPTION_RECORD
 _EXCEPTION_REGISTRATION_RECORD
 _EX_FAST_REF
 _EX_PUSH_LOCK
 _EX_PUSH_LOCK_CACHE_AWARE
 _EX_PUSH_LOCK_WAIT_BLOCK
 _EX_RUNDOWN_REF
 _FAST_IO_DISPATCH
 _FAST_MUTEX
 _FILE_BASIC_INFORMATION
 _FILE_GET_QUOTA_INFORMATION
 _FILE_NETWORK_OPEN_INFORMATION
 _FILE_OBJECT
 _FILE_STANDARD_INFORMATION
 _FLOATING_SAVE_AREA
 _FNSAVE_FORMAT
 _FS_FILTER_CALLBACKS
 _FS_FILTER_CALLBACK_DATA
 _FS_FILTER_PARAMETERS
 _FXSAVE_FORMAT
 _FX_SAVE_AREA
 _GDI_TEB_BATCH
 _GENERAL_LOOKASIDE
 _GENERIC_MAPPING
 _GUID
 _HANDLE_TABLE
 _HANDLE_TRACE_DB_ENTRY
 _HANDLE_TRACE_DEBUG_INFO
 _HARDWARE_PTE_X86
 _HEAP
 _HEAP_ENTRY
 _HEAP_LOCK
 _HEAP_PSEUDO_TAG_ENTRY
 _HEAP_SEGMENT
 _HEAP_TAG_ENTRY
 _HEAP_UCR_SEGMENT
 _HEAP_UNCOMMMTTED_RANGE
 _IMAGE_DATA_DIRECTORY
 _IMAGE_FILE_HEADER
 _IMAGE_NT_HEADERS
 _IMAGE_OPTIONAL_HEADER
 _INITIAL_PRIVILEGE_SET
 _INTERFACE
 _IO_CLIENT_EXTENSION
 _IO_COMPLETION_CONTEXT
 _IO_COUNTERS
 _IO_RESOURCE_DESCRIPTOR
 _IO_RESOURCE_LIST
 _IO_RESOURCE_REQUIREMENTS_LIST
 _IO_SECURITY_CONTEXT
 _IO_STACK_LOCATION
 _IO_STATUS_BLOCK
 _IO_TIMER
 _IRP
 _KAPC
 _KAPC_STATE
 _KDEVICE_QUEUE
 _KDEVICE_QUEUE_ENTRY
 _KDPC
 _KDPC_DATA
 _KEVENT
 _KEXECUTE_OPTIONS
 _KGATE
 _KGDTENTRY
 _KGUARDED_MUTEX
 _KIDTENTRY
 _KNODE
 _KPCR
 _KPRCB
 _KPROCESS
 _KPROCESSOR_STATE
 _KQUEUE
 _KSEMAPHORE
 _KSPECIAL_REGISTERS
 _KSPIN_LOCK_QUEUE
 _KSYSTEM_TIME
 _KTHREAD
 _KTIMER
 _KTRAP_FRAME
 _KTSS
 _KUSER_SHARED_DATA
 _KWAIT_BLOCK
 _KiIoAccessMap
 _LARGE_INTEGER
 _LDR_DATA_TABLE_ENTRY
 _LIST_ENTRY
 _LUID
 _LUID_AND_ATTRIBUTES
 _MAILSLOT_CREATE_PARAMETERS
 _MDL
 _MMADDRESS_NODE
 _MMSUPPORT
 _MMSUPPORT_FLAGS
 _MMWSL
 _MM_AVL_TABLE
 _NAMED_PIPE_CREATE_PARAMETERS
 _NPAGED_LOOKASIDE_LIST
 _NT_TIB
 _OBJECT_ATTRIBUTES
 _OBJECT_CREATE_INFORMATION
 _OBJECT_DIRECTORY
 _OBJECT_DIRECTORY_ENTRY
 _OBJECT_DUMP_CONTROL
 _OBJECT_HANDLE_COUNT_DATABASE
 _OBJECT_HANDLE_COUNT_ENTRY
 _OBJECT_HANDLE_INFORMATION
 _OBJECT_HEADER
 _OBJECT_HEADER_CREATOR_INFO
 _OBJECT_HEADER_HANDLE_INFO
 _OBJECT_HEADER_NAME_INFO
 _OBJECT_HEADER_QUOTA_INFO
 _OBJECT_NAME_INFORMATION
 _OBJECT_TYPE
 _OBJECT_TYPE_INITIALIZER
 _OWNER_ENTRY
 _PAGED_LOOKASIDE_LIST
 _PAGEFAULT_HISTORY
 _PEB
 _PEB_FREE_BLOCK
 _PEB_LDR_DATA
 _PERFINFO_GROUPMASK
 _POWER_SEQUENCE
 _POWER_STATE
 _PP_LOOKASIDE_LIST
 _PRIVILEGE_SET
 _PROCESSOR_POWER_STATE
 _PROCESS_WS_WATCH_INFORMATION
 _PS_IMPERSONATION_INFORMATION
 _PS_JOB_TOKEN_FILTER
 _QUAD
 _RTL_ACTIVATION_CONTEXT_STACK_FRAME
 _RTL_AVL_TABLE
 _RTL_BALANCED_LINKS
 _RTL_CRITICAL_SECTION
 _RTL_CRITICAL_SECTION_DEBUG
 _RTL_DRIVE_LETTER_CURDIR
 _RTL_STACK_TRACE_ENTRY
 _RTL_TRACE_BLOCK
 _RTL_TRACE_DATABASE
 _RTL_TRACE_SEGMENT
 _RTL_USER_PROCESS_PARAMETERS
 _SCSI_REQUEST_BLOCK
 _SECTION_OBJECT_POINTERS
 _SECURITY_QUALITY_OF_SERVICE
 _SECURITY_SUBJECT_CONTEXT
 _SE_AUDIT_PROCESS_CREATION_INFO
 _SID
 _SID_AND_ATTRIBUTES
 _SID_IDENTIFIER_AUTHORITY
 _SINGLE_LIST_ENTRY
 _SLIST_HEADER
 _STACK_TRACE_DATABASE
 _STRING
 _TEB
 _TEB_ACTIVE_FRAME
 _TEB_ACTIVE_FRAME_CONTEXT
 _TERMINATION_PORT
 _ULARGE_INTEGER
 _UNICODE_STRING
 _VPB
 _WAIT_CONTEXT_BLOCK
 __unnamed
 _flags</description>
		<content:encoded><![CDATA[<p>In case anyone is interested, the output from the above is 275 unique data types&#8230;<br />
     PROCESSOR_IDLE_TIMES<br />
     _CLIENT_ID<br />
     _CM_PARTIAL_RESOURCE_LIST<br />
     _CONTEXT<br />
     _CURDIR<br />
     _DESCRIPTOR<br />
     _DISPATCHER_HEADER<br />
     _ERESOURCE<br />
     _EX_FAST_REF<br />
     _EX_PUSH_LOCK<br />
     _EX_RUNDOWN_REF<br />
     _FAST_MUTEX<br />
     _FLOATING_SAVE_AREA<br />
     _FNSAVE_FORMAT<br />
     _FS_FILTER_PARAMETERS<br />
     _FXSAVE_FORMAT<br />
     _FX_SAVE_AREA<br />
     _GDI_TEB_BATCH<br />
     _GENERAL_LOOKASIDE<br />
     _GENERIC_MAPPING<br />
     _HARDWARE_PTE_X86<br />
     _HEAP_ENTRY<br />
     _IMAGE_FILE_HEADER<br />
     _IMAGE_OPTIONAL_HEADER<br />
     _INITIAL_PRIVILEGE_SET<br />
     _IO_COUNTERS<br />
     _IO_STATUS_BLOCK<br />
     _KAPC<br />
     _KAPC_STATE<br />
     _KDEVICE_QUEUE<br />
     _KDEVICE_QUEUE_ENTRY<br />
     _KDPC<br />
     _KEVENT<br />
     _KEXECUTE_OPTIONS<br />
     _KGATE<br />
     _KGDTENTRY<br />
     _KGUARDED_MUTEX<br />
     _KIDTENTRY<br />
     _KPRCB<br />
     _KPROCESS<br />
     _KPROCESSOR_STATE<br />
     _KSEMAPHORE<br />
     _KSPECIAL_REGISTERS<br />
     _KSYSTEM_TIME<br />
     _KTHREAD<br />
     _KTIMER<br />
     _LARGE_INTEGER<br />
     _LIST_ENTRY<br />
     _LUID<br />
     _MMADDRESS_NODE<br />
     _MMSUPPORT<br />
     _MMSUPPORT_FLAGS<br />
     _MM_AVL_TABLE<br />
     _NT_TIB<br />
     _OBJECT_HANDLE_COUNT_ENTRY<br />
     _OBJECT_TYPE_INITIALIZER<br />
     _POWER_STATE<br />
     _PRIVILEGE_SET<br />
     _PROCESSOR_POWER_STATE<br />
     _QUAD<br />
     _RTL_AVL_TABLE<br />
     _RTL_BALANCED_LINKS<br />
     _RTL_CRITICAL_SECTION<br />
     _SECURITY_QUALITY_OF_SERVICE<br />
     _SECURITY_SUBJECT_CONTEXT<br />
     _SE_AUDIT_PROCESS_CREATION_INFO<br />
     _SID<br />
     _SID_IDENTIFIER_AUTHORITY<br />
     _SINGLE_LIST_ENTRY<br />
     _SLIST_HEADER<br />
     _STRING<br />
     _ULARGE_INTEGER<br />
     _UNICODE_STRING<br />
     _WAIT_CONTEXT_BLOCK<br />
     __unnamed<br />
     _flags<br />
 LIST_ENTRY32<br />
 LIST_ENTRY64<br />
 PROCESSOR_IDLE_TIMES<br />
 PROCESSOR_PERF_STATE<br />
 _ACCESS_STATE<br />
 _ACTIVATION_CONTEXT<br />
 _ACTIVATION_CONTEXT_DATA<br />
 _ACTIVATION_CONTEXT_STACK<br />
 _ASSEMBLY_STORAGE_MAP<br />
 _CLIENT_ID<br />
 _CM_FULL_RESOURCE_DESCRIPTOR<br />
 _CM_PARTIAL_RESOURCE_DESCRIPTOR<br />
 _CM_PARTIAL_RESOURCE_LIST<br />
 _CM_RESOURCE_LIST<br />
 _COMPRESSED_DATA_INFO<br />
 _CONTEXT<br />
 _CURDIR<br />
 _DESCRIPTOR<br />
 _DEVICE_CAPABILITIES<br />
 _DEVICE_MAP<br />
 _DEVICE_OBJECT<br />
 _DEVICE_OBJECT_POWER_EXTENSION<br />
 _DEVOBJ_EXTENSION<br />
 _DISPATCHER_HEADER<br />
 _DPH_BLOCK_INFORMATION<br />
 _DPH_HEAP_BLOCK<br />
 _DPH_HEAP_ROOT<br />
 _DRIVER_EXTENSION<br />
 _DRIVER_OBJECT<br />
 _EJOB<br />
 _EPROCESS<br />
 _EPROCESS_QUOTA_BLOCK<br />
 _EPROCESS_QUOTA_ENTRY<br />
 _ERESOURCE<br />
 _ETHREAD<br />
 _EXCEPTION_RECORD<br />
 _EXCEPTION_REGISTRATION_RECORD<br />
 _EX_FAST_REF<br />
 _EX_PUSH_LOCK<br />
 _EX_PUSH_LOCK_CACHE_AWARE<br />
 _EX_PUSH_LOCK_WAIT_BLOCK<br />
 _EX_RUNDOWN_REF<br />
 _FAST_IO_DISPATCH<br />
 _FAST_MUTEX<br />
 _FILE_BASIC_INFORMATION<br />
 _FILE_GET_QUOTA_INFORMATION<br />
 _FILE_NETWORK_OPEN_INFORMATION<br />
 _FILE_OBJECT<br />
 _FILE_STANDARD_INFORMATION<br />
 _FLOATING_SAVE_AREA<br />
 _FNSAVE_FORMAT<br />
 _FS_FILTER_CALLBACKS<br />
 _FS_FILTER_CALLBACK_DATA<br />
 _FS_FILTER_PARAMETERS<br />
 _FXSAVE_FORMAT<br />
 _FX_SAVE_AREA<br />
 _GDI_TEB_BATCH<br />
 _GENERAL_LOOKASIDE<br />
 _GENERIC_MAPPING<br />
 _GUID<br />
 _HANDLE_TABLE<br />
 _HANDLE_TRACE_DB_ENTRY<br />
 _HANDLE_TRACE_DEBUG_INFO<br />
 _HARDWARE_PTE_X86<br />
 _HEAP<br />
 _HEAP_ENTRY<br />
 _HEAP_LOCK<br />
 _HEAP_PSEUDO_TAG_ENTRY<br />
 _HEAP_SEGMENT<br />
 _HEAP_TAG_ENTRY<br />
 _HEAP_UCR_SEGMENT<br />
 _HEAP_UNCOMMMTTED_RANGE<br />
 _IMAGE_DATA_DIRECTORY<br />
 _IMAGE_FILE_HEADER<br />
 _IMAGE_NT_HEADERS<br />
 _IMAGE_OPTIONAL_HEADER<br />
 _INITIAL_PRIVILEGE_SET<br />
 _INTERFACE<br />
 _IO_CLIENT_EXTENSION<br />
 _IO_COMPLETION_CONTEXT<br />
 _IO_COUNTERS<br />
 _IO_RESOURCE_DESCRIPTOR<br />
 _IO_RESOURCE_LIST<br />
 _IO_RESOURCE_REQUIREMENTS_LIST<br />
 _IO_SECURITY_CONTEXT<br />
 _IO_STACK_LOCATION<br />
 _IO_STATUS_BLOCK<br />
 _IO_TIMER<br />
 _IRP<br />
 _KAPC<br />
 _KAPC_STATE<br />
 _KDEVICE_QUEUE<br />
 _KDEVICE_QUEUE_ENTRY<br />
 _KDPC<br />
 _KDPC_DATA<br />
 _KEVENT<br />
 _KEXECUTE_OPTIONS<br />
 _KGATE<br />
 _KGDTENTRY<br />
 _KGUARDED_MUTEX<br />
 _KIDTENTRY<br />
 _KNODE<br />
 _KPCR<br />
 _KPRCB<br />
 _KPROCESS<br />
 _KPROCESSOR_STATE<br />
 _KQUEUE<br />
 _KSEMAPHORE<br />
 _KSPECIAL_REGISTERS<br />
 _KSPIN_LOCK_QUEUE<br />
 _KSYSTEM_TIME<br />
 _KTHREAD<br />
 _KTIMER<br />
 _KTRAP_FRAME<br />
 _KTSS<br />
 _KUSER_SHARED_DATA<br />
 _KWAIT_BLOCK<br />
 _KiIoAccessMap<br />
 _LARGE_INTEGER<br />
 _LDR_DATA_TABLE_ENTRY<br />
 _LIST_ENTRY<br />
 _LUID<br />
 _LUID_AND_ATTRIBUTES<br />
 _MAILSLOT_CREATE_PARAMETERS<br />
 _MDL<br />
 _MMADDRESS_NODE<br />
 _MMSUPPORT<br />
 _MMSUPPORT_FLAGS<br />
 _MMWSL<br />
 _MM_AVL_TABLE<br />
 _NAMED_PIPE_CREATE_PARAMETERS<br />
 _NPAGED_LOOKASIDE_LIST<br />
 _NT_TIB<br />
 _OBJECT_ATTRIBUTES<br />
 _OBJECT_CREATE_INFORMATION<br />
 _OBJECT_DIRECTORY<br />
 _OBJECT_DIRECTORY_ENTRY<br />
 _OBJECT_DUMP_CONTROL<br />
 _OBJECT_HANDLE_COUNT_DATABASE<br />
 _OBJECT_HANDLE_COUNT_ENTRY<br />
 _OBJECT_HANDLE_INFORMATION<br />
 _OBJECT_HEADER<br />
 _OBJECT_HEADER_CREATOR_INFO<br />
 _OBJECT_HEADER_HANDLE_INFO<br />
 _OBJECT_HEADER_NAME_INFO<br />
 _OBJECT_HEADER_QUOTA_INFO<br />
 _OBJECT_NAME_INFORMATION<br />
 _OBJECT_TYPE<br />
 _OBJECT_TYPE_INITIALIZER<br />
 _OWNER_ENTRY<br />
 _PAGED_LOOKASIDE_LIST<br />
 _PAGEFAULT_HISTORY<br />
 _PEB<br />
 _PEB_FREE_BLOCK<br />
 _PEB_LDR_DATA<br />
 _PERFINFO_GROUPMASK<br />
 _POWER_SEQUENCE<br />
 _POWER_STATE<br />
 _PP_LOOKASIDE_LIST<br />
 _PRIVILEGE_SET<br />
 _PROCESSOR_POWER_STATE<br />
 _PROCESS_WS_WATCH_INFORMATION<br />
 _PS_IMPERSONATION_INFORMATION<br />
 _PS_JOB_TOKEN_FILTER<br />
 _QUAD<br />
 _RTL_ACTIVATION_CONTEXT_STACK_FRAME<br />
 _RTL_AVL_TABLE<br />
 _RTL_BALANCED_LINKS<br />
 _RTL_CRITICAL_SECTION<br />
 _RTL_CRITICAL_SECTION_DEBUG<br />
 _RTL_DRIVE_LETTER_CURDIR<br />
 _RTL_STACK_TRACE_ENTRY<br />
 _RTL_TRACE_BLOCK<br />
 _RTL_TRACE_DATABASE<br />
 _RTL_TRACE_SEGMENT<br />
 _RTL_USER_PROCESS_PARAMETERS<br />
 _SCSI_REQUEST_BLOCK<br />
 _SECTION_OBJECT_POINTERS<br />
 _SECURITY_QUALITY_OF_SERVICE<br />
 _SECURITY_SUBJECT_CONTEXT<br />
 _SE_AUDIT_PROCESS_CREATION_INFO<br />
 _SID<br />
 _SID_AND_ATTRIBUTES<br />
 _SID_IDENTIFIER_AUTHORITY<br />
 _SINGLE_LIST_ENTRY<br />
 _SLIST_HEADER<br />
 _STACK_TRACE_DATABASE<br />
 _STRING<br />
 _TEB<br />
 _TEB_ACTIVE_FRAME<br />
 _TEB_ACTIVE_FRAME_CONTEXT<br />
 _TERMINATION_PORT<br />
 _ULARGE_INTEGER<br />
 _UNICODE_STRING<br />
 _VPB<br />
 _WAIT_CONTEXT_BLOCK<br />
 __unnamed<br />
 _flags</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nickdigital</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2007/02/10/exported-ntdll-and-kernel-structures/#comment-845</link>
		<dc:creator>nickdigital</dc:creator>
		<pubDate>Tue, 27 Mar 2007 22:26:43 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2007/02/10/exported-ntdll-and-kernel-structures/#comment-845</guid>
		<description>Ahh, very nice tip, I had never come across the DIA2Dump sample.  You spice this up a litte by using another Microsoft tools, logparser to filter out the duplicates and then sort Alphabetically...

c:\&#62;"C:\Program Files\Microsoft Visual Studio 8\DIA SDK\Samples\DIA2Dump\Release\Dia2Dump.e
xe" -t C:\websymbols\ntdll.pdb\DCE823FCF71A4BF5AA489994520EA18F2\ntdll.pdb &#124; logparser.exe -i:TEXTLI
NE -o:CSV "Select DISTINCT EXTRACT_SUFFIX(TEXT,0,':') AS Type From STDIN WHERE TEXT LIKE '%UDT%' ORD
ER BY Type ASC"</description>
		<content:encoded><![CDATA[<p>Ahh, very nice tip, I had never come across the DIA2Dump sample.  You spice this up a litte by using another Microsoft tools, logparser to filter out the duplicates and then sort Alphabetically&#8230;</p>
<p>c:\&gt;&#8221;C:\Program Files\Microsoft Visual Studio 8\DIA SDK\Samples\DIA2Dump\Release\Dia2Dump.e<br />
xe&#8221; -t C:\websymbols\ntdll.pdb\DCE823FCF71A4BF5AA489994520EA18F2\ntdll.pdb | logparser.exe -i:TEXTLI<br />
NE -o:CSV &#8220;Select DISTINCT EXTRACT_SUFFIX(TEXT,0,&#8217;:') AS Type From STDIN WHERE TEXT LIKE &#8216;%UDT%&#8217; ORD<br />
ER BY Type ASC&#8221;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
