MCPcopy Create free account

hub / github.com/ELMERIKH/PyinMemoryPE / functions

Functions2,770 in github.com/ELMERIKH/PyinMemoryPE

↓ 10,015 callersFunctionmake_flag
(name, value)
windows/generated_def/flag.py:48
↓ 1,794 callersMethodregister_ntstatus
(cls, code, name, descr)
windows/generated_def/ntstatus.py:31
↓ 192 callersMethodsizeof
Return size of the structure.
pythonmemorymodule/pefile.py:1001
↓ 86 callersMethodfrom_int
(cls, size, x)
windows/native_exec/simple_x86.py:74
↓ 82 callersMethodfrom_int
(cls, size, x)
windows/native_exec/simple_x64.py:79
↓ 63 callersMethodpack
Pack a PSID :param PSID psid:
windows/rpc/ndr.py:113
↓ 58 callersMethoddecode
(self, *args)
pythonmemorymodule/pefile.py:763
↓ 53 callersMethodcast
(self, type)
windows/utils/improved_buffer.py:26
↓ 47 callersMethoddbg
(self, msg, *args)
pythonmemorymodule/__init__.py:483
↓ 41 callersMethodunpack
(self, stream)
windows/rpc/ndr.py:87
↓ 39 callersMethodget
Return the value of the property ``name``. The return value depends of the type of the property and can vary
windows/winobject/wmi.py:83
↓ 38 callersFunctiongenerate_simple_getter
(function, restype, extract_value=True, doc=None)
windows/winobject/task_scheduler.py:5
↓ 34 callersMethoddump
Returns a string representation of the structure.
pythonmemorymodule/pefile.py:1055
↓ 33 callersMethod__unpack_data__
Apply structure format to raw data. Returns an unpacked structure object if successful, None otherwise.
pythonmemorymodule/pefile.py:2800
↓ 33 callersMethodadd_line
Adds a line. The line can be indented with the optional argument 'indent'.
pythonmemorymodule/pefile.py:843
↓ 33 callersMethodget_data
Get data regardless of the section where it lies on. Given a RVA and the size of the chunk to retrieve, this method will find the sec
pythonmemorymodule/pefile.py:5874
↓ 33 callersMethodwrite_memory
Write `data` at `addr`
windows/winobject/process.py:1058
↓ 32 callersMethodadd_newline
Adds a newline.
pythonmemorymodule/pefile.py:861
↓ 30 callersMethodfrom_string
(cls, strsid)
windows/generated_def/winstructs.py:208
↓ 30 callersMethoditems
(self)
windows/winobject/wmi.py:167
↓ 28 callersMethodadd_lines
Adds a list of lines. The list can be indented with the optional argument 'indent'.
pythonmemorymodule/pefile.py:835
↓ 28 callersMethodget_offset_from_rva
Get the file offset corresponding to this RVA. Given a RVA , this method will find the section where the data lies and return the off
pythonmemorymodule/pefile.py:5939
↓ 19 callersMethodadd_header
Adds a header element.
pythonmemorymodule/pefile.py:857
↓ 19 callersMethodfrom_buffer
(self, data)
windows/crypto/cryptmsg.py:126
↓ 17 callersMethodDisabledMemoryBreakpoint
A context-manager that disable all memory breakpoints and restore them on exit
windows/debug/debugger.py:1022
↓ 16 callersMethodfrom_buffer_copy
(self, buffer)
windows/utils/improved_buffer.py:87
↓ 14 callersMethodread_memory
Read ``size`` from ``addr`` :return: The data read :rtype: :class:`str`
windows/winobject/process.py:1077
↓ 14 callersMethodupdate
(self, blob, final)
windows/crypto/cryptmsg.py:116
↓ 13 callersMethod_get_type_info
(self, typeinfo, ires=None)
windows/debug/symbols.py:156
↓ 13 callersMethodadd
Adds some text, no newline will be appended. The text can be indented with the optional argument 'indent'.
pythonmemorymodule/pefile.py:850
↓ 13 callersMethodget_code
(self)
windows/native_exec/simple_x86.py:943
↓ 13 callersFunctiontwo_way_dict
(pairs)
pythonmemorymodule/pefile.py:136
↓ 12 callersFunctionb
(x)
pythonmemorymodule/pefile.py:720
↓ 12 callersMethodfrom_string
(cls, str_base)
windows/native_exec/simple_x64.py:70
↓ 12 callersMethodget_exception_context
Return context of current exception
windows/debug/localdbg.py:72
↓ 12 callersMethodpartial_unpack
(self, format)
windows/rpc/ndr.py:554
↓ 12 callersMethodset_context
(self, context)
windows/debug/localdbg.py:26
↓ 12 callersMethodvalues
(self)
windows/winobject/wmi.py:170
↓ 11 callersMethodcount
(self)
windows/generated_def/winstructs.py:7291
↓ 11 callersFunctioncreate_prefix
(name, value)
windows/native_exec/simple_x86.py:100
↓ 11 callersFunctioncreate_prefix
(name, value)
windows/native_exec/simple_x64.py:118
↓ 11 callersMethoddword_align
(self, offset, base)
pythonmemorymodule/pefile.py:5199
↓ 10 callersMethodnormalize_import_va
(self, va)
pythonmemorymodule/pefile.py:5202
↓ 10 callersFunctionretrieve_flags
Read the flags from a dictionary and return them in a usable form. Will return a list of (flag, value) for all flags in "flag_dict" matching
pythonmemorymodule/pefile.py:687
↓ 10 callersMethodvirtual_protect
Change the access right of one or more page of the process
windows/winobject/process.py:170
↓ 9 callersMethod_killed_in_action
Return ``True`` if current process have been detached by user callback
windows/debug/debugger.py:151
↓ 9 callersMethod_update_debugger_state
(self, debug_event)
windows/debug/debugger.py:222
↓ 9 callersFunctiondword_pad
(s)
windows/rpc/ndr.py:29
↓ 9 callersMethodfrom_buffer
(self, buffer)
windows/alpc.py:144
↓ 9 callersMethodfrom_string
(cls, str_base)
windows/native_exec/simple_x86.py:65
↓ 9 callersMethodget_code
(self)
windows/native_exec/simple_x86.py:975
↓ 9 callersMethodget_code
(self)
windows/native_exec/simple_x64.py:1124
↓ 9 callersMethodget_reg_bits
(cls, name)
windows/native_exec/simple_x86.py:272
↓ 9 callersMethodget_string_u_at_rva
Get an Unicode string located at the given address.
pythonmemorymodule/pefile.py:5988
↓ 9 callersFunctiontransform_pyobject_to_pvoid
(obj)
windows/winproxy/apis/dbghelp.py:17
↓ 9 callersMethodwrite
(self, data)
windows/rpc/ndr.py:598
↓ 8 callersMethod__init__
(self, handle=0, channel=None, timeout=None)
windows/winobject/event_log.py:71
↓ 8 callersFunctionadd_simple_setter
(getter, function, restype)
windows/winobject/task_scheduler.py:15
↓ 8 callersMethodget_alignment
(self)
windows/rpc/ndr.py:130
↓ 8 callersMethodget_file_offset
(self)
pythonmemorymodule/pefile.py:990
↓ 8 callersMethodget_param
(self, param_type, index=0, raw=False)
windows/crypto/cryptmsg.py:20
↓ 8 callersMethodget_string_at_rva
Get an ASCII string located at the given address.
pythonmemorymodule/pefile.py:5960
↓ 8 callersMethodis_new_reg
(name)
windows/native_exec/simple_x64.py:160
↓ 8 callersMethodkeys
The properties of the object (include system properties)
windows/winobject/wmi.py:160
↓ 8 callersMethodproperty
(self, type, index)
windows/winobject/event_log.py:915
↓ 8 callersMethodvalue
Retrieve a value from the event. ``name`` is an XPath expressions that uniquely identify a node or attribute in the event. (see https:
windows/winobject/event_log.py:170
↓ 8 callersMethodwrite_qword
write a qword at ``addr``
windows/winobject/process.py:407
↓ 7 callersFunctionbuffer
(obj, eltclass=None)
windows/utils/improved_buffer.py:117
↓ 7 callersMethodfrom_string
Return a new :class:`SecurityDescriptor` from the ``SDDL``. :returns: :class:`SecurityDescriptor` .. warning:: At the m
windows/security.py:807
↓ 7 callersMethodget_section_by_rva
Get the section containing the given address.
pythonmemorymodule/pefile.py:6040
↓ 7 callersFunctionget_string
(target, addr)
windows/pe_parse.py:98
↓ 7 callersMethodread_memory
(self, addr, size)
windows/syswow64.py:189
↓ 7 callersMethodset_bytes_at_offset
Overwrite the bytes at the given file offset with the given string. Return True if successful, False otherwise. It can fail if the of
pythonmemorymodule/pefile.py:6954
↓ 6 callersFunctionVirtualAlloc
(lpAddress=0, dwSize=NeededParameter, flAllocationType=gdef.MEM_COMMIT, flProtect=gdef.PAGE_EXECUTE_READWRITE)
windows/winproxy/apis/kernel32.py:237
↓ 6 callersMethod__unpack__
(self, data)
pythonmemorymodule/pefile.py:1006
↓ 6 callersMethod_from_handle
(cls, handle)
windows/winobject/process.py:762
↓ 6 callersMethodapply_to_target
(self, target)
windows/debug/breakpoints.py:20
↓ 6 callersMethodclose
(self)
pythonmemorymodule/pefile.py:2788
↓ 6 callersMethodcreate_real_implem
(item_type, nbelt)
windows/utils/improved_buffer.py:68
↓ 6 callersFunctionexplain_sid
(sid)
windows/security.py:1042
↓ 6 callersMethodfind
Return the certificate that match `issuer` and `serialnumber` :return: :class:`Certificate` -- ``None`` if certificate is not found
windows/crypto/certificate.py:162
↓ 6 callersMethodfrom_pointer
(self, ptr)
windows/crypto/certificate.py:476
↓ 6 callersMethodfrom_structure
(cls, structcls)
windows/remotectypes.py:405
↓ 6 callersFunctiongenerate_walker
(namelist, target_module)
windows/generated_def/meta.py:14868
↓ 6 callersMethodget_NT_HEADER
(self)
windows/pe_parse.py:324
↓ 6 callersMethodget_PointerToRawData_adj
(self)
pythonmemorymodule/pefile.py:1161
↓ 6 callersMethodget_reg_bits
(cls, name)
windows/native_exec/simple_x64.py:292
↓ 6 callersMethodget_word_from_data
Convert two bytes of data to a word (little endian) 'offset' is assumed to index into a word array. So setting it to N will return a
pythonmemorymodule/pefile.py:6841
↓ 6 callersMethodis_reg
(name)
windows/native_exec/simple_x86.py:136
↓ 6 callersFunctionpack_dword
(x)
windows/rpc/ndr.py:25
↓ 6 callersMethodread
(self, size)
windows/rpc/ndr.py:568
↓ 6 callersMethodreg_size
(name)
windows/native_exec/simple_x86.py:150
↓ 6 callersMethodwait
(self)
windows/winobject/bits.py:175
↓ 5 callersMethod_query_channel_metadata_property
(self, propertyid)
windows/winobject/event_log.py:574
↓ 5 callersMethod_resolve
(self, addr, target)
windows/debug/debugger.py:236
↓ 5 callersMethodaccept_arg
(self, args, instr_state)
windows/native_exec/simple_x86.py:340
↓ 5 callersMethodadd_instruction
(self, instruction)
windows/native_exec/simple_x86.py:980
↓ 5 callersMethodadd_instruction
(self, instruction)
windows/native_exec/simple_x64.py:1151
↓ 5 callersMethodadjust_FileAlignment
(self, val, file_alignment)
pythonmemorymodule/pefile.py:7382
↓ 5 callersMethodalign
(self, alignement)
windows/rpc/ndr.py:603
next →1–100 of 2,770, ranked by callers