process_context class maintains the complete state of an emulated Windows process, including threads, handles, memory structures, and Windows-specific objects.
Overview
This class serves as the central hub for process-level resources in the Windows emulator. It manages:- Process Environment Block (PEB) and process parameters
- Thread lifecycle and synchronization
- Handle tables for kernel objects (files, events, sections, etc.)
- User-mode objects (windows, desktops)
- Atoms and window classes
- WOW64 support for 32-bit applications
Constructor
x86_64_emulator&
Reference to the CPU emulator instance
memory_manager&
Reference to the memory manager for allocations
utils::clock&
System clock for time-related operations
callbacks&
Callback functions for thread lifecycle events
Methods
setup
Initializes the process context with all necessary Windows structures.x86_64_emulator&
CPU emulator instance
memory_manager&
Memory manager for virtual address space
registry_manager&
Windows registry emulation
file_system&
Virtual file system for path translation
windows_version_manager&
Windows version information provider
const application_settings&
Application-specific configuration
const mapped_module&
The main executable module
const mapped_module&
The ntdll.dll module
const apiset::container&
API set schema container for module redirection
const mapped_module*
default:"nullptr"
Optional 32-bit ntdll for WOW64 processes
create_thread
Creates a new emulated thread in the process.memory_manager&
Memory manager for thread stack allocation
uint64_t
Entry point address for the thread
uint64_t
Parameter passed to the thread function
uint64_t
Size of the thread stack in bytes
uint32_t
Thread creation flags (e.g., CREATE_SUSPENDED)
bool
default:"false"
Whether this is the process’s initial thread
Atom Management
Atoms are globally unique string identifiers used by Windows for window classes and other purposes.find_atom
std::u16string_view
The atom name to search for
std::nullopt otherwise.
add_or_find_atom
std::u16string
The atom name to add or find
delete_atom
const std::u16string&
The atom name to delete (first overload)
uint16_t
The atom ID to delete (second overload)
true if the atom was deleted, false otherwise.
get_atom_name
uint16_t
The atom ID to look up
nullptr if not found.
KnownDLLs Management
KnownDLLs are preloaded system DLLs cached as section objects.build_knowndlls_section_table
registry_manager&
Registry manager to read KnownDLLs list
const file_system&
File system for resolving DLL paths
const apiset_map&
API set schema for module redirection
const windows_path&
Windows system directory path
bool
Whether to build 32-bit or 64-bit KnownDLLs table
get_knowndll_section_by_name
const std::u16string&
DLL name (e.g., “kernel32.dll”)
bool
Whether to search in 32-bit or 64-bit table
add_knowndll_section
has_knowndll_section
get_handle_store
handle
The handle to look up
nullptr if not found.
get_live_thread_count
Serialization
Public Members
WOW64 Support
bool
Flag indicating if this is a 32-bit process running under WOW64
Process State
std::optional<NTSTATUS>
Process exit status code (set when process terminates)
Memory Structures
emulator_object<PEB64>
64-bit Process Environment Block
emulator_object<RTL_USER_PROCESS_PARAMETERS64>
64-bit process parameters (command line, environment, etc.)
std::optional<emulator_object<PEB32>>
32-bit PEB for WOW64 processes
std::optional<emulator_object<RTL_USER_PROCESS_PARAMETERS32>>
32-bit process parameters for WOW64
Critical Addresses
uint64_t
Base address of ntdll.dll
uint64_t
Address of LdrInitializeThunk (thread entry point)
uint64_t
Address of RtlUserThreadStart
uint64_t
Address of KiUserApcDispatcher
uint64_t
Address of KiUserExceptionDispatcher
Handle Stores
handle_store<handle_types::event, event>
Event object handle store
handle_store<handle_types::file, file>
File handle store
handle_store<handle_types::section, section>
Section object handle store
handle_store<handle_types::device, io_device_container>
Device handle store
handle_store<handle_types::semaphore, semaphore>
Semaphore handle store
handle_store<handle_types::thread, emulator_thread>
Thread handle store
user_handle_store<handle_types::window, window>
Window handle store (user-mode handles)
handle_store<handle_types::desktop, desktop>
Desktop handle store
Thread Management
emulator_thread*
Pointer to the currently executing thread
uint32_t
Total number of threads created
Usage Example
See Also
- module_manager - Module and DLL management
- syscall_dispatcher - System call handling
- file_system - Virtual file system