Skip to main content
The module_manager class handles loading, mapping, and managing PE (Portable Executable) modules in the emulated process. It supports both 32-bit and 64-bit modules and handles WOW64 processes.

Overview

This class provides:
  • PE file parsing and memory mapping
  • Module lifetime management
  • Support for both native 64-bit and WOW64 (32-bit on 64-bit) execution
  • Module lookup by address or name
  • KnownDLLs optimization
  • Module load counting and duplicate handling

Enums

execution_mode

Defines the execution mode for the emulated process.

Structures

pe_detection_result

Result of PE architecture detection.
winpe::pe_arch
Detected PE architecture (x86, x64, etc.)
execution_mode
Recommended execution mode based on architecture
std::string
Error description if detection failed

callbacks

Callback functions for module lifecycle events.

wow64_modules

WOW64-specific module references.

Constructor

memory_manager&
Memory manager for module allocations
file_system&
Virtual file system for resolving module paths
callbacks&
Callback functions for module events

Methods

map_main_modules

Loads the main executable and core system modules.
const windows_path&
Path to the main executable
windows_version_manager&
Windows version manager
process_context&
Process context to initialize
const logger&
Logger for diagnostic output
This method:
  • Detects the executable architecture
  • Determines execution mode (native 64-bit or WOW64)
  • Loads ntdll.dll and other core modules
  • Sets up the WOW64 environment if needed

map_module

Maps a module from the virtual file system.
windows_path
Windows-style path to the module
const logger&
Logger instance
bool
default:"false"
Whether this is a statically loaded module
bool
default:"false"
Allow loading the same module multiple times
Returns: Pointer to the mapped module, or nullptr on failure.

map_local_module

Maps a module from the host file system.
const std::filesystem::path&
Host filesystem path to the PE file
windows_path
Virtual Windows path for the module
const logger&
Logger instance
bool
default:"false"
Static module flag
bool
default:"false"
Allow duplicates flag
Returns: Pointer to the mapped module, or nullptr on failure.

map_memory_module

Maps a module that’s already loaded in memory.
uint64_t
Base address of the module in memory
uint64_t
Size of the module image
windows_path
Virtual path for the module
const logger&
Logger instance
bool
default:"false"
Static module flag
bool
default:"false"
Allow duplicates flag
Returns: Pointer to the mapped module, or nullptr on failure.

find_by_address

Finds a module containing the specified address.
uint64_t
Address to search for
Returns: Pointer to the module, or nullptr if not found.

find_by_name

Finds a module by its name.
std::string_view
Module name to search for (e.g., “kernel32.dll”)
Returns: Pointer to the module, or nullptr if not found.

find_name

Retrieves the name of the module at the given address.
uint64_t
Address to look up
Returns: Module name string, or “<N/A>” if not found.

unmap

Unmaps a module from memory.
uint64_t
Base address of the module to unmap
Returns: true if unmapped successfully, false otherwise.

get_module_load_count_by_path

Retrieves the number of times a module has been loaded.
const windows_path&
Module path
Returns: Load count if the module has been loaded.

modules

Returns: Map of all loaded modules (keyed by base address).

Execution Mode

Returns: Current execution mode or WOW64 status.

Serialization

Serialization support for saving/loading module state.

Public Members

mapped_module*
Pointer to the main executable module
mapped_module*
Pointer to ntdll.dll
mapped_module*
Pointer to win32u.dll
wow64_modules
WOW64-specific module pointers
std::map<std::filesystem::path, uint64_t>
Load count for each module path

Helper Classes

pe_architecture_detector

Static methods for detecting PE architecture.

module_mapping_strategy

Abstract base class for PE mapping strategies.
Implementations:
  • pe32_mapping_strategy - Maps 32-bit PE files
  • pe64_mapping_strategy - Maps 64-bit PE files

Usage Example

See Also