!pte
!pte [VirtualAddress (hex)] [pid ProcessId (hex)]
nt!ExAllocatePoolWithTag
.nt!ExAllocatePoolWithTag+5
.fffff80040f00c28
.fffff8003ad6f010
. Note that some entries might have a large PDE and no PTE.IOCTL = IOCTL_DEBUGGER_READ_PAGE_TABLE_ENTRIES_DETAILS
, you have to send it in the following structure.MemoryMapper.h
but they might be outdated.