import ctypes, struct
from ctypes import wintypes

kernel32 = ctypes.windll.kernel32
advapi32 = ctypes.windll.advapi32

hToken = wintypes.HANDLE()
if advapi32.OpenProcessToken(kernel32.GetCurrentProcess(), 0x0020 | 0x0008, ctypes.byref(hToken)):
    luid = wintypes.LARGE_INTEGER()
    if advapi32.LookupPrivilegeValueW(None, "SeDebugPrivilege", ctypes.byref(luid)):
        class TP(ctypes.Structure):
            _fields_ = [('Count', wintypes.DWORD), ('Luid', wintypes.LARGE_INTEGER), ('Attr', wintypes.DWORD)]
        tp = TP(1, luid, 2)
        advapi32.AdjustTokenPrivileges(hToken, False, ctypes.byref(tp), ctypes.sizeof(tp), None, None)
    kernel32.CloseHandle(hToken)

pid = 32572
h = kernel32.OpenProcess(0x10 | 0x400, False, pid)
buf = (ctypes.c_char * 64)()
kernel32.ReadProcessMemory(h, ctypes.c_void_p(0x10B786D4 - 24), buf, 64, None)
data = bytes(buf)
ints = [struct.unpack_from('<i', data, o)[0] for o in range(0, 64, 4)]
with open(r"C:\Projects\JX\logs\debug_pid_32572.txt", "w") as f:
    f.write(f"PID {pid} ints at 0x10B786D4-24: {ints}\n")

# Also check VirtualQueryEx on 0x10B786D4
class MBI(ctypes.Structure):
    _fields_ = [('BaseAddress', ctypes.c_void_p), ('AllocationBase', ctypes.c_void_p), ('AllocationProtect', wintypes.DWORD), ('RegionSize', ctypes.c_size_t), ('State', wintypes.DWORD), ('Protect', wintypes.DWORD), ('Type', wintypes.DWORD)]
mbi = MBI()
kernel32.VirtualQueryEx(h, ctypes.c_void_p(0x10B786D4), ctypes.byref(mbi), ctypes.sizeof(mbi))
with open(r"C:\Projects\JX\logs\debug_pid_32572.txt", "a") as f:
    f.write(f"MBI at 0x10B786D4: Base=0x{mbi.BaseAddress:X}, Alloc=0x{mbi.AllocationBase:X}, Size=0x{mbi.RegionSize:X}, State=0x{mbi.State:X}, Protect=0x{mbi.Protect:X}\n")
