Overview
Thewindows_emulator class is the primary interface for Windows user-space emulation. It manages the entire emulation environment including memory, processes, threads, file system, registry, and network operations.
Constructor
std::unique_ptr<x86_64_emulator>
required
The underlying x86-64 CPU emulator instance
const emulator_settings&
default:"{}"
Configuration settings for the emulator
emulator_callbacks
default:"{}"
Event callbacks for monitoring emulation events
emulator_interfaces
default:"{}"
Optional custom implementations for clock and socket factory
Alternative Constructor with Application
application_settings
required
Application configuration including path, working directory, and arguments
Public Members
Thewindows_emulator class exposes several public components:
emulator_callbacks
Event callbacks for monitoring emulation behavior
logger
Logging interface for emulation events
file_system
Virtual file system manager
memory_manager
Memory management interface
registry_manager
Windows registry manager
windows_version_manager
Windows version information manager
module_manager
Module/DLL loading and management
process_context
Process and thread context information
syscall_dispatcher
System call dispatcher
Methods
emu()
clock()
socket_factory()
current_thread()
std::runtime_error if no active thread exists
Source: windows_emulator.hpp:146
get_executed_instructions()
setup_process_if_necessary()
start()
size_t
default:"0"
Number of instructions to execute. 0 means run indefinitely until stopped.
stop()
serialize() / deserialize()
utils::buffer_serializer&
required
Buffer to serialize to or deserialize from
save_snapshot() / restore_snapshot()
Port Mapping Methods
get_host_port()
uint16_t
required
The port number in the emulator
get_emulator_port()
uint16_t
required
The port number on the host
map_port()
uint16_t
required
The port number in the emulator
uint16_t
required
The port number on the host
Thread Management
yield_thread()
bool
default:"false"
Whether the thread should be alertable during yield
perform_thread_switch()
true if a thread switch occurred, false otherwise
Source: windows_emulator.hpp:212
activate_thread()
uint32_t
required
The thread ID to activate
true if activation succeeded, false otherwise
Source: windows_emulator.hpp:213
Supporting Types
emulator_settings
bool
default:"false"
Disable logging output
bool
default:"false"
Use relative time instead of system time
std::filesystem::path
default:""
Root directory for emulation environment
std::filesystem::path
default:"./registry"
Directory containing registry hives
std::unordered_map<uint16_t, uint16_t>
default:"{}"
Port number mappings between emulator and host
std::unordered_map<windows_path, std::filesystem::path>
default:"{}"
Path mappings between Windows and host paths
application_settings
windows_path
required
Path to the executable to run
windows_path
Working directory for the application
std::vector<std::u16string>
Command-line arguments for the application
emulator_interfaces
std::unique_ptr<utils::clock>
Custom clock implementation (defaults to system clock)
std::unique_ptr<network::socket_factory>
Custom socket factory implementation
Usage Example
Notes
- The
windows_emulatorclass is non-copyable and non-movable - The destructor automatically cleans up all resources
- Thread switching is managed automatically during emulation
- Snapshots allow for quick state rollback without full serialization overhead