MCPcopy Create free account

hub / github.com/ELMERIKH/PyinMemoryPE / functions

Functions2,770 in github.com/ELMERIKH/PyinMemoryPE

↓ 3 callersFunctiontransform_type_to_remote64bits
(ftype)
windows/remotectypes.py:463
↓ 3 callersMethodwith_all_attributes
Create a new :class:`MessageAttribute` with the following attributes allocated: - :class:`ALPC_MESSAGE_SECURITY_ATTRIBUTE` -
windows/alpc.py:220
↓ 3 callersMethodwrap_up
(self)
pythonmemorymodule/pefile.py:1353
↓ 3 callersMethodwrite_code
(self, code)
windows/native_exec/native_function.py:49
↓ 2 callersFunctionBUFFER
(type, nbelt=None)
windows/utils/improved_buffer.py:112
↓ 2 callersMethodIMAGE_FIRST_SECTION
(self)
pythonmemorymodule/__init__.py:660
↓ 2 callersMethodRelease
Default ``Release`` implementation that returns ``1``
windows/com.py:353
↓ 2 callersMethodTO_LDR_ENTRY
(self)
windows/winobject/process.py:1275
↓ 2 callersMethod__get_word_value_at_rva
(self, rva)
pythonmemorymodule/pefile.py:786
↓ 2 callersMethod__init__
(self, addr, target)
windows/remotectypes.py:173
↓ 2 callersMethod__init__
(self, typeid, modbase, resolver)
windows/debug/symbols.py:150
↓ 2 callersMethod__init__
(self, *initial_args)
windows/native_exec/simple_x64.py:1118
↓ 2 callersMethod__repr__
(self)
windows/generated_def/winstructs.py:225
↓ 2 callersMethod_extract_alpc_attributes_values
(self, value)
windows/alpc.py:272
↓ 2 callersMethod_finish_debug_event
(self, event, action)
windows/debug/debugger.py:205
↓ 2 callersMethod_forge_call_request
(self, interface_nb, method_offset, params, ipid=None)
windows/rpc/client.py:126
↓ 2 callersMethod_from_name_and_type
(cls, objname, objtype, flags=DEFAULT_SECURITY_INFORMATION, query_sacl=False)
windows/security.py:829
↓ 2 callersMethod_get_loaded_dll
(self, load_dll)
windows/debug/debugger.py:719
↓ 2 callersMethod_get_principal_teb_addr
(self)
windows/winobject/process.py:868
↓ 2 callersMethod_get_priv_by_name
(self, name)
windows/winobject/token.py:84
↓ 2 callersMethod_get_request_type
raise if request_type == RESPONSE_TYPE_FAIL
windows/rpc/client.py:174
↓ 2 callersMethod_get_time
(self)
windows/winobject/event_trace.py:147
↓ 2 callersMethod_lookup_name
(self, luid)
windows/winobject/token.py:115
↓ 2 callersMethod_open_key
(self, handle, name, sam)
windows/winobject/registry.py:159
↓ 2 callersMethod_parse_event_template_data_element
(self, element)
windows/winobject/event_log.py:977
↓ 2 callersMethod_pass_memory_breakpoint
(self, bp, page_protect, fault_page)
windows/debug/debugger.py:523
↓ 2 callersMethod_post_unpack
(cls, result)
windows/rpc/ndr.py:447
↓ 2 callersMethod_send_request
(self, request)
windows/rpc/client.py:122
↓ 2 callersMethod_setup_pending_breakpoints_new_thread
(self, new_thread)
windows/debug/debugger.py:466
↓ 2 callersMethod_str_ipv6_addr
(addr)
windows/winobject/network.py:92
↓ 2 callersMethod_unpack_bitfield_attributes
Replace compound attributes corresponding to bitfields with separate sub-fields.
pythonmemorymodule/pefile.py:1496
↓ 2 callersMethod_user_and_computer_name
(self)
windows/winobject/token.py:284
↓ 2 callersFunctionaccept_as_32immediat
(x)
windows/native_exec/simple_x64.py:354
↓ 2 callersFunctionaccept_as_8immediat
(x)
windows/native_exec/simple_x86.py:301
↓ 2 callersFunctionaccept_as_8immediat
(x)
windows/native_exec/simple_x64.py:327
↓ 2 callersMethodadd_pending_breakpoint
(self, bp, target)
windows/debug/debugger.py:268
↓ 2 callersMethodassemble
(self, code)
windows/native_exec/simple_x86.py:1108
↓ 2 callersMethodcode
(self)
windows/debug/debugger.py:37
↓ 2 callersMethodcompute_displacement
(self, displacement, force_displacement=0)
windows/native_exec/simple_x86.py:522
↓ 2 callersMethodcompute_displacement
(self, displacement, force_displacement=0)
windows/native_exec/simple_x64.py:704
↓ 2 callersMethodcopy
(self)
windows/native_exec/simple_x86.py:31
↓ 2 callersFunctioncount_zeroes
(data)
pythonmemorymodule/pefile.py:90
↓ 2 callersFunctioncreate_displacement
Creates a X86 memory access description
windows/native_exec/simple_x86.py:175
↓ 2 callersFunctioncreate_displacement
(base=None, index=None, scale=None, disp=0, prefix=None)
windows/native_exec/simple_x64.py:197
↓ 2 callersFunctioncreate_unsigned_buffer
(sz, indata)
pythonmemorymodule/__init__.py:459
↓ 2 callersFunctiondecode_registry_buffer
(type, buffer, size)
windows/winobject/registry.py:134
↓ 2 callersMethoddiff
(self)
pythonmemorymodule/pefile.py:740
↓ 2 callersMethoddisable_all_memory_breakpoints
Restore all pages to their original access rights. If target is ``None``, use ``current_process`` :return: a mapping of all dis
windows/debug/debugger.py:981
↓ 2 callersFunctiondo_cpuid
Performs a CPUID for the current process bitness :rtype: :class:`X86CpuidResult`
windows/native_exec/cpuid.py:110
↓ 2 callersMethoddump
(self)
windows/winobject/exception.py:130
↓ 2 callersMethoddump
(self)
windows/native_exec/simple_x86.py:37
↓ 2 callersMethoddump
(self)
windows/native_exec/simple_x64.py:34
↓ 2 callersMethoddump_dict
Dump all the PE header information into a dictionary.
pythonmemorymodule/pefile.py:6482
↓ 2 callersFunctionencode_init_vector
(data)
windows/crypto/encrypt_decrypt.py:9
↓ 2 callersMethodenumerate_services
(self)
windows/winobject/service.py:113
↓ 2 callersMethodenumerate_threads_generator
()
windows/winobject/system.py:455
↓ 2 callersMethodexecute
Execute some native code in the context of the process :return: The thread executing the code :rtype: :class:`WinThread` or :class:`D
windows/winobject/process.py:187
↓ 2 callersFunctionexecute_python_code
(process, code)
windows/injection.py:388
↓ 2 callersFunctionexplain_acl
(acl, sdtype=None)
windows/security.py:1162
↓ 2 callersMethodextract_arguments_32bits
(self, cproc, cthread)
windows/debug/breakpoints.py:102
↓ 2 callersMethodextract_arguments_64bits
(self, cproc, cthread)
windows/debug/breakpoints.py:126
↓ 2 callersMethodflush
Flush the trace
windows/winobject/event_trace.py:222
↓ 2 callersMethodforce_resolution
()
windows/syswow64.py:223
↓ 2 callersFunctionformatOrdString
(ord_val)
pythonmemorymodule/ordlookup/__init__.py:17
↓ 2 callersMethodfrom_raw_buffer
(cls, buffer)
windows/winobject/event_trace.py:355
↓ 2 callersMethodfrom_size
(cls, size)
windows/generated_def/winstructs.py:4364
↓ 2 callersFunctionfull_pipe_address
Return the full address of the pipe `addr`
windows/pipe.py:15
↓ 2 callersMethodfunc
(self, idx)
windows/com.py:51
↓ 2 callersFunctiongenerate_64bits_execution_stub_from_syswow
shellcode must NOT end by a ret
windows/syswow64.py:31
↓ 2 callersMethodget_EXPORT_DIRECTORY
(self)
windows/pe_parse.py:376
↓ 2 callersMethodget_ace
Retrieve ``ACE`` number ``i`` :return: :class:`Ace`
windows/security.py:623
↓ 2 callersMethodget_arg
(self, nb, proc, thread)
windows/debug/breakpoints.py:66
↓ 2 callersFunctionget_catalog_for_filename
(filename)
windows/wintrust.py:86
↓ 2 callersMethodget_data
(self)
windows/rpc/ndr.py:593
↓ 2 callersMethodget_data_from_dword
Return a four byte string representing the double word value (little endian).
pythonmemorymodule/pefile.py:6787
↓ 2 callersMethodget_data_from_qword
Return an eight byte string representing the quad-word value (little endian).
pythonmemorymodule/pefile.py:6887
↓ 2 callersMethodget_data_from_word
Return a two byte string representing the word value. (little endian).
pythonmemorymodule/pefile.py:6837
↓ 2 callersFunctionget_dll_name_from_python_version
()
windows/injection.py:325
↓ 2 callersMethodget_entropy
Calculate and return the entropy for the section.
pythonmemorymodule/pefile.py:1295
↓ 2 callersMethodget_file_version
(self, name)
windows/winobject/system.py:398
↓ 2 callersMethodget_hash_md5
Get the MD5 hex-digest of the section's data.
pythonmemorymodule/pefile.py:1318
↓ 2 callersMethodget_hash_sha1
Get the SHA-1 hex-digest of the section's data.
pythonmemorymodule/pefile.py:1300
↓ 2 callersMethodget_hash_sha256
Get the SHA-256 hex-digest of the section's data.
pythonmemorymodule/pefile.py:1306
↓ 2 callersMethodget_hash_sha512
Get the SHA-512 hex-digest of the section's data.
pythonmemorymodule/pefile.py:1312
↓ 2 callersMethodget_import_table
(self, rva, max_length=None, contains_addresses=False)
pythonmemorymodule/pefile.py:5641
↓ 2 callersMethodget_item
Return elements nb ``index``. Collection index starts at 1
windows/winobject/task_scheduler.py:31
↓ 2 callersFunctionget_kernel32_dll_name
()
windows/injection.py:21
↓ 2 callersMethodget_logical_configuration
(self, type)
windows/winobject/device_manager.py:236
↓ 2 callersMethodget_mapped_filename
The filename mapped at address ``addr`` or ``None`` :rtype: :class:`unicode` or ``None``
windows/winobject/process.py:289
↓ 2 callersMethodget_name
Retrieve the subject or issuer name of the certificate. See `CertGetNameStringA <https://msdn.microsoft.com/en-us/library/windows/desktop/aa37
windows/crypto/certificate.py:233
↓ 2 callersMethodget_new_page
(self, size)
windows/native_exec/native_function.py:30
↓ 2 callersMethodget_next_resource_descriptor
(self, resource, resdes=None)
windows/winobject/device_manager.py:297
↓ 2 callersMethodget_overlay_data_start_offset
Get the offset of data appended to the file and not contained within the area described in the headers.
pythonmemorymodule/pefile.py:7302
↓ 2 callersMethodget_property
(self, property)
windows/winobject/device_manager.py:115
↓ 2 callersMethodget_qword_from_data
Convert eight bytes of data to a word (little endian) 'offset' is assumed to index into a word array. So setting it to N will return
pythonmemorymodule/pefile.py:6891
↓ 2 callersMethodget_rva_from_offset
Get the RVA corresponding to this file offset.
pythonmemorymodule/pefile.py:5908
↓ 2 callersFunctionget_sublang_name_for_lang
(lang_value, sublang_value)
pythonmemorymodule/pefile.py:651
↓ 2 callersMethodhas_relocs
Checks if the PE file has relocation directory
pythonmemorymodule/pefile.py:6059
↓ 2 callersMethodis_32b_reg
(name)
windows/native_exec/simple_x64.py:167
↓ 2 callersMethodis_allocated
Return ``True`` if ``attribute`` is allocated
windows/alpc.py:252
← previousnext →201–300 of 2,770, ranked by callers