diff --git a/snippets/alpc_conn.py b/snippets/alpc_conn.py index 95ff57b..3a459ba 100644 --- a/snippets/alpc_conn.py +++ b/snippets/alpc_conn.py @@ -26,7 +26,7 @@ def main(): """ argc_ = len(sys.argv) if (1 == argc_): - portTypeAddr = getOffset("nt", "AlpcPortObjectType") + portTypeAddr = getOffset("nt!AlpcPortObjectType") if (0 != portTypeAddr): objTable = typedVar("nt!_EPROCESS", getCurrentProcess()).ObjectTable lstAlpcPorts = ntobj.getListByHandleTable(objTable, ptrPtr(portTypeAddr))