S1lkys / GetProcAddress

GetProcAddress implementation in C# walking the PEB using only ReadProcessMemory

Home Page:https://ricardojoserf.github.io/getprocaddress/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

GetProcAddress - C# implementation

It works like the GetProcAddress WinAPI: it takes a DLL handle and a function name or ordinal, walks the PEB structure and returns the function address.

It only uses the NtReadVirtualMemory native API call, without using structs.

It works in both 32-bit and 64-bit processes. You can test this using the binaries in the Releases section:

img


Sources

About

GetProcAddress implementation in C# walking the PEB using only ReadProcessMemory

https://ricardojoserf.github.io/getprocaddress/


Languages

Language:C# 100.0%