Overview
Theemulator_callbacks struct provides a comprehensive set of optional callback functions for monitoring and controlling Windows emulator behavior. Callbacks enable instrumentation, debugging, and custom behavior during emulation.
Definition
module_manager::callbacks- Module loading/unloading eventsprocess_context::callbacks- Process and thread events
Callback Types
All callbacks useopt_func (alias for utils::optional_function) which allows them to be unset (null) by default.
Exception Callbacks
on_exception
Memory Callbacks
on_memory_protect
uint64_t
Starting address of the memory region
uint64_t
Size of the memory region in bytes
memory_permission
New memory protection flags (read/write/exec)
on_memory_allocate
uint64_t
Starting address of the allocated region
uint64_t
Size of the allocation in bytes
memory_permission
Memory protection flags for the allocation
bool
Whether the memory is committed (true) or just reserved (false)
on_memory_violate
uint64_t
Address where the violation occurred
uint64_t
Size of the attempted access
memory_operation
Type of operation (read/write/exec)
memory_violation_type
Violation type (unmapped or protection violation)
CPU Instruction Callbacks
on_rdtsc
on_rdtscp
on_instruction
uint64_t
Virtual address of the instruction being executed
System Call Callbacks
on_syscall
uint32_t
The system call number/ID
std::string_view
Name of the system call (e.g., “NtCreateFile”)
instruction_hook_continuation indicating whether to execute or skip the syscall
instruction_hook_continuation::run_instruction- Execute the syscallinstruction_hook_continuation::skip_instruction- Skip the syscall
I/O and Activity Callbacks
on_stdout
std::string_view
The data written to stdout
on_debug_string
std::string_view
The debug message
on_ioctrl
io_device&
Reference to the I/O device
std::u16string_view
Name of the device (UTF-16)
ULONG
IOCTL control code
Activity Tracking Callbacks
on_generic_access
std::string_view
Type of resource being accessed (e.g., “file”, “registry”)
std::u16string_view
Name/path of the resource (UTF-16)
on_generic_activity
std::string_view
Description of the activity
on_suspicious_activity
std::string_view
Description of the suspicious activity
Related Types
instruction_hook_continuation
memory_operation
memory_permission when used to describe the type of memory access.
memory_violation_type
unmapped- Accessing unmapped memoryprotection- Permission violation (e.g., writing to read-only memory)
Usage Example
Module Management Callbacks
These callbacks are inherited frommodule_manager::callbacks and track DLL loading/unloading.
on_module_load
Called when a module (DLL or EXE) is loaded into memory.mapped_module&
Reference to the loaded module
on_module_unload
Called when a module is unloaded from memory.mapped_module&
Reference to the module being unloaded
Thread Management Callbacks
These callbacks are inherited fromprocess_context::callbacks and track thread lifecycle.
on_thread_create
Called when a new thread is created.handle
Handle to the new thread
emulator_thread&
Reference to the new thread object
on_thread_terminated
Called when a thread terminates.handle
Handle to the terminated thread
emulator_thread&
Reference to the terminated thread object
on_thread_switch
Called when the emulator switches between threads (context switch).emulator_thread&
Thread being switched away from
emulator_thread&
Thread being switched to
on_thread_set_name
Called when a thread’s name is set (via SetThreadDescription or similar).emulator_thread&
Thread whose name was set
Performance Considerations
- Callbacks like
on_instructionare called very frequently and can significantly impact performance - Keep callback implementations lightweight
- Avoid heavy I/O operations in hot-path callbacks
- Use filtering in callbacks to minimize overhead
- Consider batching output instead of printing on every callback
- Thread callbacks (
on_thread_switch) can be called frequently in multi-threaded programs
Notes
- All callbacks are optional (can be left unset/null)
- Callbacks are synchronous and block emulation
- Return values (like in
on_syscall) control emulator behavior emulator_callbacksinherits from bothmodule_manager::callbacksandprocess_context::callbacks- UTF-16 strings (std::u16string_view) are used for Windows path/name parameters
- Module and thread callbacks use
callback_listoroptional_functionfor multiple subscribers