Skip to main content

Overview

The windows_emulator class is the primary interface for Windows user-space emulation. It manages the entire emulation environment including memory, processes, threads, file system, registry, and network operations.

Constructor

Creates a new Windows emulator instance.
std::unique_ptr<x86_64_emulator>
required
The underlying x86-64 CPU emulator instance
const emulator_settings&
default:"{}"
Configuration settings for the emulator
emulator_callbacks
default:"{}"
Event callbacks for monitoring emulation events
emulator_interfaces
default:"{}"
Optional custom implementations for clock and socket factory

Alternative Constructor with Application

Creates a new Windows emulator with application settings.
application_settings
required
Application configuration including path, working directory, and arguments

Public Members

The windows_emulator class exposes several public components:
emulator_callbacks
Event callbacks for monitoring emulation behavior
logger
Logging interface for emulation events
file_system
Virtual file system manager
memory_manager
Memory management interface
registry_manager
Windows registry manager
windows_version_manager
Windows version information manager
module_manager
Module/DLL loading and management
process_context
Process and thread context information
syscall_dispatcher
System call dispatcher

Methods

emu()

Returns a reference to the underlying CPU emulator. Returns: Reference to the x86-64 emulator instance Source: windows_emulator.hpp:116

clock()

Returns a reference to the emulator’s clock. Returns: Reference to the clock interface Source: windows_emulator.hpp:126

socket_factory()

Returns a reference to the socket factory for network operations. Returns: Reference to the socket factory Source: windows_emulator.hpp:136

current_thread()

Returns the currently active emulator thread. Returns: Reference to the active thread Throws: std::runtime_error if no active thread exists Source: windows_emulator.hpp:146

get_executed_instructions()

Returns the total number of instructions executed. Returns: Count of executed instructions Source: windows_emulator.hpp:156

setup_process_if_necessary()

Initializes the process environment if not already set up. Source: windows_emulator.hpp:161

start()

Starts or resumes emulation.
size_t
default:"0"
Number of instructions to execute. 0 means run indefinitely until stopped.
Source: windows_emulator.hpp:163

stop()

Stops the emulation. Source: windows_emulator.hpp:164

serialize() / deserialize()

Serializes or deserializes the emulator state.
utils::buffer_serializer&
required
Buffer to serialize to or deserialize from
Source: windows_emulator.hpp:166

save_snapshot() / restore_snapshot()

Saves or restores a snapshot of the emulator state for quick rollback. Source: windows_emulator.hpp:169

Port Mapping Methods

get_host_port()

Returns the host port mapped to an emulator port.
uint16_t
required
The port number in the emulator
Returns: The mapped host port, or the emulator port if no mapping exists Source: windows_emulator.hpp:172

get_emulator_port()

Returns the emulator port mapped to a host port.
uint16_t
required
The port number on the host
Returns: The mapped emulator port, or the host port if no mapping exists Source: windows_emulator.hpp:183

map_port()

Creates a port mapping between emulator and host.
uint16_t
required
The port number in the emulator
uint16_t
required
The port number on the host
Source: windows_emulator.hpp:196

Thread Management

yield_thread()

Yields execution of the current thread.
bool
default:"false"
Whether the thread should be alertable during yield
Source: windows_emulator.hpp:211

perform_thread_switch()

Performs a thread context switch if one is pending. Returns: true if a thread switch occurred, false otherwise Source: windows_emulator.hpp:212

activate_thread()

Activates a thread by its ID.
uint32_t
required
The thread ID to activate
Returns: true if activation succeeded, false otherwise Source: windows_emulator.hpp:213

Supporting Types

emulator_settings

Configuration settings for the emulator.
bool
default:"false"
Disable logging output
bool
default:"false"
Use relative time instead of system time
std::filesystem::path
default:""
Root directory for emulation environment
std::filesystem::path
default:"./registry"
Directory containing registry hives
std::unordered_map<uint16_t, uint16_t>
default:"{}"
Port number mappings between emulator and host
std::unordered_map<windows_path, std::filesystem::path>
default:"{}"
Path mappings between Windows and host paths

application_settings

Settings for the application to run in the emulator.
windows_path
required
Path to the executable to run
windows_path
Working directory for the application
std::vector<std::u16string>
Command-line arguments for the application

emulator_interfaces

Optional custom interface implementations.
std::unique_ptr<utils::clock>
Custom clock implementation (defaults to system clock)
std::unique_ptr<network::socket_factory>
Custom socket factory implementation

Usage Example

Notes

  • The windows_emulator class is non-copyable and non-movable
  • The destructor automatically cleans up all resources
  • Thread switching is managed automatically during emulation
  • Snapshots allow for quick state rollback without full serialization overhead