Skip to content

Instantly share code, notes, and snippets.

@tandasat
Last active June 21, 2023 00:23
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save tandasat/a4092484c63b0390b45e93140f080795 to your computer and use it in GitHub Desktop.
Save tandasat/a4092484c63b0390b45e93140f080795 to your computer and use it in GitHub Desktop.
EPT setup dumped on Windows 10.0.22621.1848 using hvext: https://github.com/tandasat/hvext
kd> !dump_ept
Current EPT pointer 0x11b8bc09e
GPA PA Flags
0x0 - 0x1000 -> Identity ------WR
0x1000 - 0x2000 -> Identity ---U--WR
0x3000 - 0x9f000 -> Identity ---U--WR
0x9f000 - 0x100000 -> Identity ------WR
0x100000 - 0xa46000 -> Identity ---U--WR
0xa47000 - 0x4c00000 -> Identity ---U--WR
0x5000000 - 0xa201000 -> Identity ---U--WR
0xa201000 - 0xa202000 -> Identity ---U---R
0xa202000 - 0xa203000 -> Identity ---U--WR
0xa203000 - 0xa204000 -> Identity ---U---R
0xa204000 - 0xa400000 -> Identity ---U--WR
0xa5b8000 - 0xa5c4000 -> Identity ---U--WR
0xa797000 - 0xa79d000 -> Identity ---U--WR
0xa7a1000 - 0xa7a4000 -> Identity ---U--WR
0xa800000 - 0x4c6cb000 -> Identity ---U--WR
0x4c6cb000 - 0x4c87e000 -> Identity ------WR
0x4c87e000 - 0x4c87f000 -> Identity ---U-X-R
0x4c87f000 - 0x4c883000 -> Identity ------WR
0x4c883000 - 0x4c885000 -> Identity ---U-X-R
0x4c885000 - 0x4c889000 -> Identity ------WR
0x4c889000 - 0x4c88c000 -> Identity ---U-X-R
0x4c88c000 - 0x4c890000 -> Identity ------WR
0x4c890000 - 0x4c892000 -> Identity ---U-X-R
0x4c892000 - 0x4c896000 -> Identity ------WR
0x4c896000 - 0x4c89b000 -> Identity ---U-X-R
0x4c89b000 - 0x4c8a0000 -> Identity ------WR
0x4c8a0000 - 0x4c8a1000 -> Identity ---U-X-R
0x4c8a1000 - 0x4c8a6000 -> Identity ------WR
0x4c8a6000 - 0x4c8a7000 -> Identity ---U-X-R
0x4c8a7000 - 0x4c8ac000 -> Identity ------WR
0x4c8ac000 - 0x4c8ae000 -> Identity ---U-X-R
0x4c8ae000 - 0x4c8b3000 -> Identity ------WR
0x4c8b3000 - 0x4c8b4000 -> Identity ---U-X-R
0x4c8b4000 - 0x4c8b8000 -> Identity ------WR
0x4c8b8000 - 0x4c8bc000 -> Identity ---U-X-R
0x4c8bc000 - 0x4c8c1000 -> Identity ------WR
0x4c8c1000 - 0x4c8c4000 -> Identity ---U-X-R
0x4c8c4000 - 0x4c8c9000 -> Identity ------WR
0x4c8c9000 - 0x4c8cb000 -> Identity ---U-X-R
0x4c8cb000 - 0x4c8cf000 -> Identity ------WR
0x4c8cf000 - 0x4c8d0000 -> Identity ---U-X-R
0x4c8d0000 - 0x4c8d5000 -> Identity ------WR
0x4c8d5000 - 0x4c8d6000 -> Identity ---U-X-R
0x4c8d6000 - 0x4c8db000 -> Identity ------WR
0x4c8db000 - 0x4c8dc000 -> Identity ---U-X-R
0x4c8dc000 - 0x4c8e0000 -> Identity ------WR
0x4c8e0000 - 0x4c8e4000 -> Identity ---U-X-R
0x4c8e4000 - 0x4c8e9000 -> Identity ------WR
0x4c8e9000 - 0x4c8ea000 -> Identity ---U-X-R
0x4c8ea000 - 0x60d11000 -> Identity ------WR
0x60d11000 - 0x61800000 -> Identity ---U--WR
0x61800000 - 0xfed20000 -> Identity ------WR
0xfed20000 - 0xfed21000 -> 0x11b894000 -------R
0xfed21000 - 0xfed30000 -> Identity ------WR
0xfed30000 - 0xfed31000 -> Identity -------R
0xfed31000 - 0xfed90000 -> Identity ------WR
0xfed90000 - 0xfed91000 -> 0x11b894000 -------R
0xfed91000 - 0xfed92000 -> 0x11b894000 -------R
0xfed92000 - 0x100000000 -> Identity ------WR
0x100000000 - 0x100400000 -> Identity ---U--WR
0x100a54000 - 0x100a55000 -> Identity -------R
0x100a5b000 - 0x100a5c000 -> Identity -------R
0x1023d3000 - 0x1023e3000 -> Identity ------WR
0x102400000 - 0x105200000 -> Identity ---U--WR
0x105200000 - 0x105600000 -> Identity ---U---R
0x105600000 - 0x106c00000 -> Identity ---U--WR
0x106c00000 - 0x106e00000 -> Identity ---U---R
0x106e00000 - 0x108600000 -> Identity ---U--WR
0x108600000 - 0x108800000 -> Identity ---U---R
0x108800000 - 0x109200000 -> Identity ---U--WR
0x109200000 - 0x109600000 -> Identity ---U---R
0x109600000 - 0x10a600000 -> Identity ---U--WR
0x10a600000 - 0x10aa00000 -> Identity ---U---R
0x10aa00000 - 0x116800000 -> Identity ---U--WR
0x116942000 - 0x11694e000 -> Identity ------WR
0x11694e000 - 0x116a00000 -> Identity ---U--WR
0x119002000 - 0x119003000 -> Identity ------WR
0x119011000 - 0x119014000 -> Identity ------WR
0x1193f1000 - 0x1193f2000 -> Identity -------R
0x119933000 - 0x119934000 -> Identity ---U-X-R
0x119935000 - 0x119936000 -> Identity -------R
0x11b8ba000 - 0x11b8bb000 -> Identity -------R
0x11c000000 - 0x11c200000 -> Identity ---U--WR
0x11c200000 - 0x11cc00000 -> Identity ---U-X-R
0x11cc00000 - 0x11ce00000 -> Identity ---U--WR
0x11ce00000 - 0x11cea8000 -> Identity ---U---R
0x11cea8000 - 0x11ceaa000 -> Identity -------R
0x11ceaa000 - 0x11d000000 -> Identity ---U---R
0x11d000000 - 0x11ee00000 -> Identity ---U--WR
0x121000000 - 0x121200000 -> Identity ---U-X-R
0x121200000 - 0x121400000 -> Identity S------R
0x121400000 - 0x121600000 -> Identity ---U---R
0x121600000 - 0x123800000 -> Identity ---U--WR
0x123800000 - 0x123a00000 -> Identity ---U-X-R
0x123a00000 - 0x126600000 -> Identity ---U--WR
0x126600000 - 0x126800000 -> Identity ---U---R
0x126800000 - 0x127a00000 -> Identity ---U--WR
0x127a00000 - 0x127c00000 -> Identity ---U-X-R
0x127c00000 - 0x128000000 -> Identity ---U--WR
0x128000000 - 0x128200000 -> Identity ---U-X-R
0x128200000 - 0x128800000 -> Identity ---U--WR
0x128800000 - 0x128a00000 -> Identity ---U-X-R
0x128a00000 - 0x13ee00000 -> Identity ---U--WR
0x13f000000 - 0x14bc00000 -> Identity ---U--WR
0x14bc00000 - 0x14be00000 -> Identity S------R
0x14be00000 - 0x1d6400000 -> Identity ---U--WR
0x1d6400000 - 0x1d6600000 -> Identity S------R
0x1d6600000 - 0x384200000 -> Identity ---U--WR
0x384200000 - 0x384400000 -> Identity ---U---R
0x384400000 - 0x385200000 -> Identity ---U--WR
0x385200000 - 0x385400000 -> Identity ---U-X-R
0x385400000 - 0x388200000 -> Identity ---U--WR
0x388200000 - 0x388400000 -> Identity ---U-X-R
0x388400000 - 0x391e00000 -> Identity ---U--WR
0x391e00000 - 0x392000000 -> Identity ---U---R
0x392000000 - 0x392200000 -> Identity ---U--WR
0x392200000 - 0x392400000 -> Identity ---U-X-R
0x392400000 - 0x393c00000 -> Identity ---U--WR
0x393c00000 - 0x393e00000 -> Identity ---U---R
0x393e00000 - 0x396000000 -> Identity ---U--WR
0x396000000 - 0x396200000 -> Identity ---U-X-R
0x396200000 - 0x396b71000 -> Identity ---U--WR
0x396b77000 - 0x396ba4000 -> Identity ---U--WR
0x396ba7000 - 0x396bba000 -> Identity ---U--WR
0x396bbd000 - 0x399e00000 -> Identity ---U--WR
0x399e00000 - 0x39a000000 -> Identity ---U-X-R
0x39a000000 - 0x39f600000 -> Identity ---U--WR
0x39f600000 - 0x39f800000 -> Identity ---U-X-R
0x39f800000 - 0x3a7000000 -> Identity ---U--WR
0x3a7000000 - 0x3a7200000 -> Identity ---U-X-R
0x3a7200000 - 0x3a8400000 -> Identity ---U--WR
0x3a8400000 - 0x3a8600000 -> Identity ---U-X-R
0x3a8600000 - 0x3acc00000 -> Identity ---U--WR
0x3acc00000 - 0x3ace00000 -> Identity ---U---R
0x3ace00000 - 0x3ae200000 -> Identity ---U--WR
0x3ae200000 - 0x3ae400000 -> Identity ---U---R
0x3ae400000 - 0x3b4000000 -> Identity ---U--WR
0x3b4000000 - 0x3b4200000 -> Identity ---U---R
0x3b4200000 - 0x3b5000000 -> Identity ---U--WR
0x3b5000000 - 0x3b5200000 -> Identity ---U---R
0x3b5200000 - 0x3c0400000 -> Identity ---U--WR
0x3c0400000 - 0x3c0600000 -> Identity ---U-X-R
0x3c0600000 - 0x3ce800000 -> Identity ---U--WR
0x3ce800000 - 0x3cea00000 -> Identity ---U---R
0x3cea00000 - 0x3d3a00000 -> Identity ---U--WR
0x3d3a00000 - 0x3d3c00000 -> Identity ---U---R
0x3d3c00000 - 0x3d7c00000 -> Identity ---U--WR
0x3d7c00000 - 0x3d7e00000 -> Identity ---U---R
0x3d7e00000 - 0x3dd200000 -> Identity ---U--WR
0x3dd200000 - 0x3dd400000 -> Identity ---U---R
0x3dd400000 - 0x3e1400000 -> Identity ---U--WR
0x3e1400000 - 0x3e1600000 -> Identity ---U---R
0x3e1600000 - 0x3e5200000 -> Identity ---U--WR
0x3e5200000 - 0x3e5400000 -> Identity ---U---R
0x3e5400000 - 0x3e8c00000 -> Identity ---U--WR
0x3e8c00000 - 0x3e8e00000 -> Identity ---U---R
0x3e8e00000 - 0x3f5800000 -> Identity ---U--WR
0x3f5800000 - 0x3f6e00000 -> Identity ---U---R
0x3f6e00000 - 0x3f7000000 -> Identity ---U-X-R
0x3f7000000 - 0x3f7600000 -> Identity ---U--WR
0x3f7600000 - 0x3f7a00000 -> Identity ---U-X-R
0x3f7a00000 - 0x3f7c00000 -> Identity ---U---R
0x3f7c00000 - 0x3f8e00000 -> Identity ---U--WR
0x3f8e00000 - 0x3f9000000 -> Identity ---U---R
0x3f9000000 - 0x3f9001000 -> 0x11b894000 ---U---R
0x3f9001000 - 0x3f9002000 -> 0x11b894000 ---U---R
0x3f9002000 - 0x3f9003000 -> 0x11b894000 ---U---R
0x3f9003000 - 0x3f9004000 -> 0x11b894000 ---U---R
0x3f9004000 - 0x3f9005000 -> 0x11b894000 ---U---R
0x3f9005000 - 0x3f9006000 -> 0x11b894000 ---U---R
0x3f9200000 - 0x3fa200000 -> Identity ---U--WR
0x3fa200000 - 0x3fa400000 -> Identity ---U-X-R
0x3fa400000 - 0x3fa600000 -> Identity ---U---R
0x3fa600000 - 0x3fa800000 -> Identity ---U-X-R
0x3fa800000 - 0x3fae00000 -> Identity ---U--WR
0x3fae00000 - 0x3fb000000 -> Identity ---U-X-R
0x3fb000000 - 0x40f800000 -> Identity ---U--WR
0x40f800000 - 0x40fa00000 -> Identity S------R
0x40fa00000 - 0x448000000 -> Identity ---U--WR
0x448000000 - 0x448200000 -> Identity ---U-X-R
0x448200000 - 0x448600000 -> Identity ---U--WR
0x448600000 - 0x448800000 -> Identity ---U-X-R
0x448800000 - 0x44a400000 -> Identity ---U--WR
0x44a400000 - 0x44a800000 -> Identity ---U-X-R
0x44a800000 - 0x44c000000 -> Identity ---U--WR
0x44c000000 - 0x44c200000 -> Identity ---U---R
0x44c200000 - 0x44ca00000 -> Identity ---U--WR
0x44ca00000 - 0x44cc00000 -> Identity ---U-X-R
0x44cc00000 - 0x44e600000 -> Identity ---U--WR
0x44e600000 - 0x44e800000 -> Identity ---U-X-R
0x44e800000 - 0x44f200000 -> Identity ---U--WR
0x44f200000 - 0x44f400000 -> Identity ---U-X-R
0x44f400000 - 0x450a00000 -> Identity ---U--WR
0x450a00000 - 0x450c00000 -> Identity ---U---R
0x450c00000 - 0x45a600000 -> Identity ---U--WR
0x45a600000 - 0x45a800000 -> Identity ---U-X-R
0x45a800000 - 0x465800000 -> Identity ---U--WR
0x465800000 - 0x465a00000 -> Identity ---U-X-R
0x465a00000 - 0x469c00000 -> Identity ---U--WR
0x469c00000 - 0x469e00000 -> Identity ---U---R
0x469e00000 - 0x46aa00000 -> Identity ---U--WR
0x46aa5d000 - 0x46aa5e000 -> Identity ---U--WR
0x46aa61000 - 0x46aa65000 -> Identity ---U--WR
0x46ab67000 - 0x46ca00000 -> Identity ---U--WR
0x46ca00000 - 0x46cc00000 -> Identity S------R
0x46cc00000 - 0x46f000000 -> Identity ---U--WR
0x46f000000 - 0x46f200000 -> Identity ---U-X-R
0x46f200000 - 0x472800000 -> Identity ---U--WR
0x472800000 - 0x472a00000 -> Identity ---U-X-R
0x472a00000 - 0x474000000 -> Identity ---U--WR
0x474000000 - 0x474200000 -> Identity ---U---R
0x474200000 - 0x476600000 -> Identity ---U--WR
0x476600000 - 0x476800000 -> Identity ---U-X-R
0x476800000 - 0x476a00000 -> Identity ---U--WR
0x476a00000 - 0x476c00000 -> Identity ---U---R
0x476c00000 - 0x477c00000 -> Identity ---U--WR
0x477c00000 - 0x477e00000 -> Identity ---U---R
0x477e00000 - 0x479600000 -> Identity ---U--WR
0x479600000 - 0x479800000 -> Identity ---U---R
0x479800000 - 0x486e00000 -> Identity ---U--WR
0x487000000 - 0x487200000 -> Identity S------R
0x487200000 - 0x487e00000 -> Identity ---U--WR
0x487e00000 - 0x488200000 -> Identity ---U-X-R
0x488200000 - 0x488400000 -> Identity ---U--WR
0x488400000 - 0x488800000 -> Identity ---U-X-R
0x488800000 - 0x488a00000 -> Identity ---U--WR
0x488a00000 - 0x488e00000 -> Identity ---U-X-R
0x488e00000 - 0x489600000 -> Identity ---U--WR
0x489600000 - 0x489753000 -> Identity ---U-X-R
0x489753000 - 0x489754000 -> Identity ---U--WR
0x489754000 - 0x489759000 -> Identity ---U-X-R
0x489759000 - 0x489767000 -> Identity ---U--WR
0x489767000 - 0x489800000 -> Identity ---U-X-R
0x489800000 - 0x489a00000 -> Identity ---U--WR
0x489a00000 - 0x489e00000 -> Identity ---U-X-R
0x489e00000 - 0x48f800000 -> Identity ---U--WR
0x4000000000 - 0x4040000000 -> Identity ------WR
0x6040000000 - 0x6080000000 -> Identity ------WR
0x7fc0000000 - 0x8000000000 -> Identity ------WR
@$dump_ept()
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment