一个python操作windows的 进程,线程,内存读写,HOOK的库
Project description
memwin介绍
一个python操作windows的 进程 线程 内存读写 HOOK的库, 暂只支持32位进程.
为什么需要创建这个库?
因为Python尽管已经有pywin32, psutil等库可以操作windows的进程线程内存,
但这些库都只是操作windows的原生api, 自己用python写的话效率低下, 要定义很多结构体才能用,
如果封装好, 就能更方便地通过hwnd来操作任意窗口进程的内存
安装
pip install memwin
文档
进程操作示例
from memwin.xprocess import XProcess
hwnd=329884
proc = XProcess(hwnd)
h_process = proc.get_h_process()
print(f"h_process: {h_process}")
线程操作示例
from memwin.xthread import XThread
hwnd=329884
thread = XThread(hwnd)
h_thread = thread.get_h_thread()
print(f"h_thread: {h_thread}")
内存读写操作示例
from memwin.xmemory import XMemory
hwnd=329884
xm = XMemory(hwnd)
teb_addr = xm.get_teb_addr()
print(f"TEB地址: {teb_addr}")
stack_top_addr = xm.read_int(teb_addr, 0x4)
print(f"栈顶指针: {stack_top_addr}")
单元测试
pip install pytest
pytest -s
上传分发包
第一次运行要装:
python3 -m pip install --user --upgrade setuptools wheel
pip install twine
以后运行这两个命令就可以打包和上传到PYPI了
python setup.py sdist build
twine upload dist/*
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
memwin-1.0.0.tar.gz
(5.8 kB
view details)
File details
Details for the file memwin-1.0.0.tar.gz.
File metadata
- Download URL: memwin-1.0.0.tar.gz
- Upload date:
- Size: 5.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/5.1.1 CPython/3.8.10
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8b57a23301e17e116f765f0cd72d014c0731dae42181a15c80c12754ec82a96b
|
|
| MD5 |
7b8f1deafed512693302fad67f618b5b
|
|
| BLAKE2b-256 |
c8aab62be75021fa699021f496036d7a659fc7b795c9e3d7ccd23ff394261950
|