viewer9 documentation

ThreadCreate PML Operation

NewTid (called "Thread ID" in Procmon) is the tid of the thread being created, as distinguished from the Tid of the event (the parent thread).

Example from 64-bit PML

Hover over field values like Time, ResultCode, CreatedTime, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

ThreadCreate opcode=1,3

ev=559

Time:2020-08-20 21:25:11.9042600
Duration:0.0000000
ResultCode:SUCCESS
Tid:6264
NewTid:2928

evdata[0-3] file offset 245721

070 0b 00 00 p...

Call Stack stacksize=16

StackAddressmodModNameModPath
0xfffff8010c5d203d383ntoskrnl.exe + 0x5d203dC:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c5eb9c8383ntoskrnl.exe + 0x5eb9c8C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c625f1f383ntoskrnl.exe + 0x625f1fC:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c625bd1383ntoskrnl.exe + 0x625bd1C:\WINDOWS\system32\ntoskrnl.exe
0xfffff80124ef4ebb522aswSnx.sys + 0x34ebbC:\WINDOWS\system32\drivers\aswSnx.sys
0xfffff80124f787e7522aswSnx.sys + 0xb87e7C:\WINDOWS\system32\drivers\aswSnx.sys
0xfffff80124f8426a522aswSnx.sys + 0xc426aC:\WINDOWS\system32\drivers\aswSnx.sys
0xfffff80124f254f6522aswSnx.sys + 0x654f6C:\WINDOWS\system32\drivers\aswSnx.sys
0xfffff80124f2543e522aswSnx.sys + 0x6543eC:\WINDOWS\system32\drivers\aswSnx.sys
0xfffff8010c099ed9383ntoskrnl.exe + 0x99ed9C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c607e15383ntoskrnl.exe + 0x607e15C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c607c20383ntoskrnl.exe + 0x607c20C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c695bc6383ntoskrnl.exe + 0x695bc6C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c1d3c15383ntoskrnl.exe + 0x1d3c15C:\WINDOWS\system32\ntoskrnl.exe
0x7ffe443bc794
0x7ffdc452010f

ThreadCreate is "Thread Create" with a space in Procmon.

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.