module_manager class handles loading, mapping, and managing PE (Portable Executable) modules in the emulated process. It supports both 32-bit and 64-bit modules and handles WOW64 processes.
Overview
This class provides:- PE file parsing and memory mapping
- Module lifetime management
- Support for both native 64-bit and WOW64 (32-bit on 64-bit) execution
- Module lookup by address or name
- KnownDLLs optimization
- Module load counting and duplicate handling
Enums
execution_mode
Defines the execution mode for the emulated process.Structures
pe_detection_result
Result of PE architecture detection.winpe::pe_arch
Detected PE architecture (x86, x64, etc.)
execution_mode
Recommended execution mode based on architecture
std::string
Error description if detection failed
callbacks
Callback functions for module lifecycle events.wow64_modules
WOW64-specific module references.Constructor
memory_manager&
Memory manager for module allocations
file_system&
Virtual file system for resolving module paths
callbacks&
Callback functions for module events
Methods
map_main_modules
Loads the main executable and core system modules.const windows_path&
Path to the main executable
windows_version_manager&
Windows version manager
process_context&
Process context to initialize
const logger&
Logger for diagnostic output
- Detects the executable architecture
- Determines execution mode (native 64-bit or WOW64)
- Loads ntdll.dll and other core modules
- Sets up the WOW64 environment if needed
map_module
Maps a module from the virtual file system.windows_path
Windows-style path to the module
const logger&
Logger instance
bool
default:"false"
Whether this is a statically loaded module
bool
default:"false"
Allow loading the same module multiple times
nullptr on failure.
map_local_module
Maps a module from the host file system.const std::filesystem::path&
Host filesystem path to the PE file
windows_path
Virtual Windows path for the module
const logger&
Logger instance
bool
default:"false"
Static module flag
bool
default:"false"
Allow duplicates flag
nullptr on failure.
map_memory_module
Maps a module that’s already loaded in memory.uint64_t
Base address of the module in memory
uint64_t
Size of the module image
windows_path
Virtual path for the module
const logger&
Logger instance
bool
default:"false"
Static module flag
bool
default:"false"
Allow duplicates flag
nullptr on failure.
find_by_address
Finds a module containing the specified address.uint64_t
Address to search for
nullptr if not found.
find_by_name
Finds a module by its name.std::string_view
Module name to search for (e.g., “kernel32.dll”)
nullptr if not found.
find_name
Retrieves the name of the module at the given address.uint64_t
Address to look up
unmap
Unmaps a module from memory.uint64_t
Base address of the module to unmap
true if unmapped successfully, false otherwise.
get_module_load_count_by_path
const windows_path&
Module path
modules
Execution Mode
Serialization
Public Members
mapped_module*
Pointer to the main executable module
mapped_module*
Pointer to ntdll.dll
mapped_module*
Pointer to win32u.dll
wow64_modules
WOW64-specific module pointers
std::map<std::filesystem::path, uint64_t>
Load count for each module path
Helper Classes
pe_architecture_detector
Static methods for detecting PE architecture.module_mapping_strategy
Abstract base class for PE mapping strategies.pe32_mapping_strategy- Maps 32-bit PE filespe64_mapping_strategy- Maps 64-bit PE files
Usage Example
See Also
- process_context - Process state management
- file_system - Virtual file system