"""D3 Q10 (control): is FUN_1800e2a40 really vtable slot +0x40 of the object that FUN_18003e370 calls? The whole action-flag attribution rests on that. Find every .rdata/.data table containing the pointer and print the slot index and neighbours; slot +0x40 = index 8. CONTROL in the same run: FUN_18013fe00 is a known vtable member? no -- instead use FUN_1801a7260, whose two DATA xrefs we already saw, and check the pointer search finds them.""" import struct, traceback try: for tag, va in (("actionflags_1800e2a40", 0x1800e2a40), ("gate_1801a7260(CONTROL: 2 DATA xrefs expected)", 0x1801a7260)): hits = find_all(struct.pack("