x64下windbg显示的进程结构体
1: kd> dt _SYSTEM_PROCESS_INFORMATION
ole32!_SYSTEM_PROCESS_INFORMATION
+0x000 NextEntryOffset : Uint4B
+0x004 NumberOfThreads : Uint4B
+0x008 WorkingSetPrivateSize : _LARGE_INTEGER
+0x010 HardFaultCount : Uint4B
+0x014 NumberOfThreadsHighWatermark : Uint4B
+0x018 CycleTime : Uint8B
+0x020 CreateTime : _LARGE_INTEGER
+0x028 UserTime : _LARGE_INTEGER
+0x030 KernelTime : _LARGE_INTEGER
+0x038 ImageName : _UNICODE_STRING
+0x048 BasePriority : Int4B
+0x050 UniqueProcessId : Ptr64 Void
+0x058 InheritedFromUniqueProcessId : Ptr64 Void
+0x060 HandleCount : Uint4B
+0x064 SessionId : Uint4B
+0x068 UniqueProcessKey : Uint8B
+0x070 PeakVirtualSize : Uint8B
+0x078 VirtualSize : Uint8B
+0x080 PageFaultCount : Uint4B
+0x088 PeakWorkingSetSize : Uint8B
+0x090 WorkingSetSize : Uint8B
+0x098 QuotaPeakPagedPoolUsage : Uint8B
+0x0a0 QuotaPagedPoolUsage : Uint8B
+0x0a8 QuotaPeakNonPagedPoolUsage : Uint8B
+0x0b0 QuotaNonPagedPoolUsage : Uint8B
+0x0b8 PagefileUsage : Uint8B
+0x0c0 PeakPagefileUsage : Uint8B
+0x0c8 PrivatePageCount : Uint8B
+0x0d0 ReadOperationCount : _LARGE_INTEGER
+0x0d8 WriteOperationCount : _LARGE_INTEGER
+0x0e0 OtherOperationCount : _LARGE_INTEGER
+0x0e8 ReadTransferCount : _LARGE_INTEGER
+0x0f0 WriteTransferCount : _LARGE_INTEGER
+0x0f8 OtherTransferCount : _LARGE_INTEGER
kd> dt _IO_COUNTERS
ole32!_IO_COUNTERS
+0x000 ReadOperationCount : Uint8B
+0x008 WriteOperationCount : Uint8B
+0x010 OtherOperationCount : Uint8B
+0x018 ReadTransferCount : Uint8B
+0x020 WriteTransferCount : Uint8B
+0x028 OtherTransferCount : Uint8B
kd> dt _VM_COUNTERS
ole32!_VM_COUNTERS
+0x000 PeakVirtualSize : Uint8B
+0x008 VirtualSize : Uint8B
+0x010 PageFaultCount : Uint4B
+0x018 PeakWorkingSetSize : Uint8B
+0x020 WorkingSetSi