struct _EPROCESS// Size=0x2e8
{
    struct _KPROCESS Pcb;// Offset=0x0 Size=0xa0
    struct _EX_PUSH_LOCK ProcessLock;// Offset=0xa0 Size=0x4
    union _LARGE_INTEGER CreateTime;// Offset=0xa8 Size=0x8
    struct _EX_RUNDOWN_REF RundownProtect;// Offset=0xb0 Size=0x4
    void * UniqueProcessId;// Offset=0xb4 Size=0x4
    struct _LIST_ENTRY ActiveProcessLinks;// Offset=0xb8 Size=0x8
    unsigned long Flags2;// Offset=0xc0 Size=0x4
    unsigned long JobNotReallyActive:1;// Offset=0xc0 Size=0x4 BitOffset=0x0 BitSize=0x1
    unsigned long AccountingFolded:1;// Offset=0xc0 Size=0x4 BitOffset=0x1 BitSize=0x1
    unsigned long NewProcessReported:1;// Offset=0xc0 Size=0x4 BitOffset=0x2 BitSize=0x1
    unsigned long ExitProcessReported:1;// Offset=0xc0 Size=0x4 BitOffset=0x3 BitSize=0x1
    unsigned long ReportCommitChanges:1;// Offset=0xc0 Size=0x4 BitOffset=0x4 BitSize=0x1
    unsigned long LastReportMemory:1;// Offset=0xc0 Size=0x4 BitOffset=0x5 BitSize=0x1
    unsigned long NoWakeCharge:1;// Offset=0xc0 Size=0x4 BitOffset=0x6 BitSize=0x1
    unsigned long HandleTableRundown:1;// Offset=0xc0 Size=0x4 BitOffset=0x7 BitSize=0x1
    unsigned long NeedsHandleRundown:1;// Offset=0xc0 Size=0x4 BitOffset=0x8 BitSize=0x1
    unsigned long RefTraceEnabled:1;// Offset=0xc0 Size=0x4 BitOffset=0x9 BitSize=0x1
    unsigned long NumaAware:1;// Offset=0xc0 Size=0x4 BitOffset=0xa BitSize=0x1
    unsigned long EmptyJobEvaluated:1;// Offset=0xc0 Size=0x4 BitOffset=0xb BitSize=0x1
    unsigned long DefaultPagePriority:3;// Offset=0xc0 Size=0x4 BitOffset=0xc BitSize=0x3
    unsigned long PrimaryTokenFrozen:1;// Offset=0xc0 Size=0x4 BitOffset=0xf BitSize=0x1
    unsigned long ProcessVerifierTarget:1;// Offset=0xc0 Size=0x4 BitOffset=0x10 BitSize=0x1
    unsigned long StackRandomizationDisabled:1;// Offset=0xc0 Size=0x4 BitOffset=0x11 BitSize=0x1
    unsigned long AffinityPermanent:1;// Offset=0xc0 Size=0x4 BitOffset=0x12 BitSize=0x1
    unsigned long AffinityUpdateEnable:1;// Offset=0xc0 Size=0x4 BitOffset=0x13 BitSize=0x1
    unsigned long PropagateNode:1;// Offset=0xc0 Size=0x4 BitOffset=0x14 BitSize=0x1
    unsigned long ExplicitAffinity:1;// Offset=0xc0 Size=0x4 BitOffset=0x15 BitSize=0x1
    unsigned long ProcessExecutionState:2;// Offset=0xc0 Size=0x4 BitOffset=0x16 BitSize=0x2
    unsigned long DisallowStrippedImages:1;// Offset=0xc0 Size=0x4 BitOffset=0x18 BitSize=0x1
    unsigned long HighEntropyASLREnabled:1;// Offset=0xc0 Size=0x4 BitOffset=0x19 BitSize=0x1
    unsigned long ExtensionPointDisable:1;// Offset=0xc0 Size=0x4 BitOffset=0x1a BitSize=0x1
    unsigned long ForceRelocateImages:1;// Offset=0xc0 Size=0x4 BitOffset=0x1b BitSize=0x1
    unsigned long ProcessStateChangeRequest:2;// Offset=0xc0 Size=0x4 BitOffset=0x1c BitSize=0x2
    unsigned long ProcessStateChangeInProgress:1;// Offset=0xc0 Size=0x4 BitOffset=0x1e BitSize=0x1
    unsigned long DisallowWin32kSystemCalls:1;// Offset=0xc0 Size=0x4 BitOffset=0x1f BitSize=0x1
    unsigned long Flags;// Offset=0xc4 Size=0x4
    unsigned long CreateReported:1;// Offset=0xc4 Size=0x4 BitOffset=0x0 BitSize=0x1
    unsigned long NoDebugInherit:1;// Offset=0xc4 Size=0x4 BitOffset=0x1 BitSize=0x1
    unsigned long ProcessExiting:1;// Offset=0xc4 Size=0x4 BitOffset=0x2 BitSize=0x1
    unsigned long ProcessDelete:1;// Offset=0xc4 Size=0x4 BitOffset=0x3 BitSize=0x1
    unsigned long Wow64SplitPages:1;// Offset=0xc4 Size=0x4 BitOffset=0x4 BitSize=0x1
    unsigned long VmDeleted:1;// Offset=0xc4 Size=0x4 BitOffset=0x5 BitSize=0x1
    unsigned long OutswapEnabled:1;// Offset=0xc4 Size=0x4 BitOffset=0x6 BitSize=0x1
    unsigned long Outswapped:1;// Offset=0xc4 Size=0x4 BitOffset=0x7 BitSize=0x1
    unsigned long ForkFailed:1;// Offset=0xc4 Size=0x4 BitOffset=0x8 BitSize=0x1
    unsigned long Wow64VaSpace4Gb:1;// Offset=0xc4 Size=0x4 BitOffset=0x9 BitSize=0x1
    unsigned long AddressSpaceInitialized:2;// Offset=0xc4 Size=0x4 BitOffset=0xa BitSize=0x2
    unsigned long SetTimerResolution:1;// Offset=0xc4 Size=0x4 BitOffset=0xc BitSize=0x1
    unsigned long BreakOnTermination:1;// Offset=0xc4 Size=0x4 BitOffset=0xd BitSize=0x1
    unsigned long DeprioritizeViews:1;// Offset=0xc4 Size=0x4 BitOffset=0xe BitSize=0x1
    unsigned long WriteWatch:1;// Offset=0xc4 Size=0x4 BitOffset=0xf BitSize=0x1
    unsigned long ProcessInSession:1;// Offset=0xc4 Size=0x4 BitOffset=0x10 BitSize=0x1
    unsigned long OverrideAddressSpace:1;// Offset=0xc4 Size=0x4 BitOffset=0x11 BitSize=0x1
    unsigned long HasAddressSpace:1;// Offset=0xc4 Size=0x4 BitOffset=0x12 BitSize=0x1
    unsigned long LaunchPrefetched:1;// Offset=0xc4 Size=0x4 BitOffset=0x13 BitSize=0x1
    unsigned long Background:1;// Offset=0xc4 Size=0x4 BitOffset=0x14 BitSize=0x1
    unsigned long VmTopDown:1;// Offset=0xc4 Size=0x4 BitOffset=0x15 BitSize=0x1
    unsigned long ImageNotifyDone:1;// Offset=0xc4 Size=0x4 BitOffset=0x16 BitSize=0x1
    unsigned long PdeUpdateNeeded:1;// Offset=0xc4 Size=0x4 BitOffset=0x17 BitSize=0x1
    unsigned long VdmAllowed:1;// Offset=0xc4 Size=0x4 BitOffset=0x18 BitSize=0x1
    unsigned long CrossSessionCreate:1;// Offset=0xc4 Size=0x4 BitOffset=0x19 BitSize=0x1
    unsigned long ProcessInserted:1;// Offset=0xc4 Size=0x4 BitOffset=0x1a BitSize=0x1
    unsigned long DefaultIoPriority:3;// Offset=0xc4 Size=0x4 BitOffset=0x1b BitSize=0x3
    unsigned long ProcessSelfDelete:1;// Offset=0xc4 Size=0x4 BitOffset=0x1e BitSize=0x1
    unsigned long SetTimerResolutionLink:1;// Offset=0xc4 Size=0x4 BitOffset=0x1f BitSize=0x1
    unsigned long ProcessQuotaUsage[2];// Offset=0xc8 Size=0x8
    unsigned long ProcessQuotaPeak[2];// Offset=0xd0 Size=0x8
    unsigned long PeakVirtualSize;// Offset=0xd8 Size=0x4
    unsigned long VirtualSize;// Offset=0xdc Size=0x4
    struct _LIST_ENTRY SessionProcessLinks;// Offset=0xe0 Size=0x8
    void * ExceptionPortData;// Offset=0xe8 Size=0x4
    unsigned long ExceptionPortValue;// Offset=0xe8 Size=0x4
    unsigned long ExceptionPortState:3;// Offset=0xe8 Size=0x4 BitOffset=0x0 BitSize=0x3
    struct _EX_FAST_REF Token;// Offset=0xec Size=0x4
    unsigned long WorkingSetPage;// Offset=0xf0 Size=0x4
    struct _EX_PUSH_LOCK AddressCreationLock;// Offset=0xf4 Size=0x4
    struct _ETHREAD * RotateInProgress;// Offset=0xf8 Size=0x4
    struct _ETHREAD * ForkInProgress;// Offset=0xfc Size=0x4
    unsigned long HardwareTrigger;// Offset=0x100 Size=0x4
    struct _EJOB * CommitChargeJob;// Offset=0x104 Size=0x4
    struct _MM_AVL_TABLE * CloneRoot;// Offset=0x108 Size=0x4
    unsigned long NumberOfPrivatePages;// Offset=0x10c Size=0x4
    unsigned long NumberOfLockedPages;// Offset=0x110 Size=0x4
    void * Win32Process;// Offset=0x114 Size=0x4
    struct _EJOB * Job;// Offset=0x118 Size=0x4
    void * SectionObject;// Offset=0x11c Size=0x4
    void * SectionBaseAddress;// Offset=0x120 Size=0x4
    unsigned long Cookie;// Offset=0x124 Size=0x4
    void * VdmObjects;// Offset=0x128 Size=0x4
    struct _PAGEFAULT_HISTORY * WorkingSetWatch;// Offset=0x12c Size=0x4
    void * Win32WindowStation;// Offset=0x130 Size=0x4
    void * InheritedFromUniqueProcessId;// Offset=0x134 Size=0x4
    void * LdtInformation;// Offset=0x138 Size=0x4
    struct _EPROCESS * CreatorProcess;// Offset=0x13c Size=0x4
    unsigned long ConsoleHostProcess;// Offset=0x13c Size=0x4
    struct _PEB * Peb;// Offset=0x140 Size=0x4
    void * Session;// Offset=0x144 Size=0x4
    void * AweInfo;// Offset=0x148 Size=0x4
    struct _EPROCESS_QUOTA_BLOCK * QuotaBlock;// Offset=0x14c Size=0x4
    struct _HANDLE_TABLE * ObjectTable;// Offset=0x150 Size=0x4
    void * DebugPort;// Offset=0x154 Size=0x4
    void * PaeTop;// Offset=0x158 Size=0x4
    void * DeviceMap;// Offset=0x15c Size=0x4
    void * EtwDataSource;// Offset=0x160 Size=0x4
    unsigned long long PageDirectoryPte;// Offset=0x168 Size=0x8
    unsigned char ImageFileName[15];// Offset=0x170 Size=0xf
    unsigned char PriorityClass;// Offset=0x17f Size=0x1
    void * SecurityPort;// Offset=0x180 Size=0x4
    struct _SE_AUDIT_PROCESS_CREATION_INFO SeAuditProcessCreationInfo;// Offset=0x184 Size=0x4
    struct _LIST_ENTRY JobLinks;// Offset=0x188 Size=0x8
    void * HighestUserAddress;// Offset=0x190 Size=0x4
    struct _LIST_ENTRY ThreadListHead;// Offset=0x194 Size=0x8
    unsigned long ActiveThreads;// Offset=0x19c Size=0x4
    unsigned long ImagePathHash;// Offset=0x1a0 Size=0x4
    unsigned long DefaultHardErrorProcessing;// Offset=0x1a4 Size=0x4
    long LastThreadExitStatus;// Offset=0x1a8 Size=0x4
    struct _EX_FAST_REF PrefetchTrace;// Offset=0x1ac Size=0x4
    struct _MM_AVL_TABLE * LockedPagesList;// Offset=0x1b0 Size=0x4
    union _LARGE_INTEGER ReadOperationCount;// Offset=0x1b8 Size=0x8
    union _LARGE_INTEGER WriteOperationCount;// Offset=0x1c0 Size=0x8
    union _LARGE_INTEGER OtherOperationCount;// Offset=0x1c8 Size=0x8
    union _LARGE_INTEGER ReadTransferCount;// Offset=0x1d0 Size=0x8
    union _LARGE_INTEGER WriteTransferCount;// Offset=0x1d8 Size=0x8
    union _LARGE_INTEGER OtherTransferCount;// Offset=0x1e0 Size=0x8
    unsigned long CommitChargeLimit;// Offset=0x1e8 Size=0x4
    unsigned long CommitCharge;// Offset=0x1ec Size=0x4
    unsigned long CommitChargePeak;// Offset=0x1f0 Size=0x4
    struct _MMSUPPORT Vm;// Offset=0x1f4 Size=0x70
    struct _LIST_ENTRY MmProcessLinks;// Offset=0x264 Size=0x8
    unsigned long ModifiedPageCount;// Offset=0x26c Size=0x4
    long ExitStatus;// Offset=0x270 Size=0x4
    struct _MM_AVL_TABLE VadRoot;// Offset=0x274 Size=0x18
    unsigned long VadPhysicalPages;// Offset=0x28c Size=0x4
    unsigned long VadPhysicalPagesLimit;// Offset=0x290 Size=0x4
    struct _ALPC_PROCESS_CONTEXT AlpcContext;// Offset=0x294 Size=0x10
    struct _LIST_ENTRY TimerResolutionLink;// Offset=0x2a4 Size=0x8
    struct _PO_DIAG_STACK_RECORD * TimerResolutionStackRecord;// Offset=0x2ac Size=0x4
    unsigned long RequestedTimerResolution;// Offset=0x2b0 Size=0x4
    unsigned long SmallestTimerResolution;// Offset=0x2b4 Size=0x4
    union _LARGE_INTEGER ExitTime;// Offset=0x2b8 Size=0x8
    unsigned long ActiveThreadsHighWatermark;// Offset=0x2c0 Size=0x4
    unsigned long LargePrivateVadCount;// Offset=0x2c4 Size=0x4
    struct _EX_PUSH_LOCK ThreadListLock;// Offset=0x2c8 Size=0x4
    void * WnfContext;// Offset=0x2cc Size=0x4
    unsigned long SectionMappingSize;// Offset=0x2d0 Size=0x4
    unsigned char SignatureLevel;// Offset=0x2d4 Size=0x1
    unsigned char SectionSignatureLevel;// Offset=0x2d5 Size=0x1
    unsigned char SpareByte20[2];// Offset=0x2d6 Size=0x2
    unsigned long KeepAliveCounter;// Offset=0x2d8 Size=0x4
    struct _PROCESS_DISK_COUNTERS * DiskCounters;// Offset=0x2dc Size=0x4
    unsigned long long LastFreezeInterruptTime;// Offset=0x2e0 Size=0x8
};