Skip to main content

一个python操作windows的 进程,线程,内存读写,HOOK的库

Project description

memwin介绍

一个python操作windows的 进程 线程 内存读写 HOOK的库, 暂只支持32位进程.
为什么需要创建这个库?
因为Python尽管已经有pywin32, psutil等库可以操作windows的进程线程内存,
但这些库都只是操作windows的原生api, 自己用python写的话效率低下, 要定义很多结构体才能用,
如果封装好, 就能更方便地通过hwnd来操作任意窗口进程的内存

安装

pip install memwin

文档

进程操作示例

from memwin.xprocess import XProcess

hwnd=329884
proc = XProcess(hwnd)
h_process = proc.get_h_process()
print(f"h_process: {h_process}")

线程操作示例

from memwin.xthread import XThread

hwnd=329884
thread = XThread(hwnd)
h_thread = thread.get_h_thread()
print(f"h_thread: {h_thread}")

内存读写操作示例

from memwin.xmemory import XMemory

hwnd=329884
xm = XMemory(hwnd)
teb_addr = xm.get_teb_addr()
print(f"TEB地址: {teb_addr}")
stack_top_addr = xm.read_int(teb_addr, 0x4)
print(f"栈顶指针: {stack_top_addr}")

单元测试

pip install pytest
pytest -s

上传分发包

第一次运行要装:

python3 -m pip install --user --upgrade setuptools wheel
pip install twine

以后运行这两个命令就可以打包和上传到PYPI了

python setup.py sdist build
twine upload dist/*

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

memwin-1.0.0.tar.gz (5.8 kB view details)

Uploaded Source

File details

Details for the file memwin-1.0.0.tar.gz.

File metadata

  • Download URL: memwin-1.0.0.tar.gz
  • Upload date:
  • Size: 5.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.8.10

File hashes

Hashes for memwin-1.0.0.tar.gz
Algorithm Hash digest
SHA256 8b57a23301e17e116f765f0cd72d014c0731dae42181a15c80c12754ec82a96b
MD5 7b8f1deafed512693302fad67f618b5b
BLAKE2b-256 c8aab62be75021fa699021f496036d7a659fc7b795c9e3d7ccd23ff394261950

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page