Skip to main content

一个python操作windows的 进程,线程,内存读写,HOOK的库

Project description

logo

Python >= 3.8 GitHub stars License win32

memwin

介绍

一个python操作windows的 进程 线程 内存读写 HOOK的库, 暂仅支持32位进程

为什么需要创建这个库?
因为Python尽管已经有pywin32, psutil等库可以操作windows的进程线程内存,
但这些库都只是操作windows的原生api, 自己用python写的话效率低下, 要定义很多结构体才能用,
如果封装好, 就能更方便地通过hwnd来操作任意窗口进程的内存

出于效率考虑, 大家只需要传入hwnd, 就可以操作任意窗口的内存,
已经查过的ID, 句柄信息会存储在实例对象中,
只要查过一次, 下次就能直接获取, 无需再次查询, 大大提高CPU的执行效率 但在使用过程中要注意, 一定要调用方法来获取对象的属性, 不要直接读属性

欢迎各位大佬 有技术的提个PR, 没技术的点个Star, 共同完善这个库~

安装

pip install memwin

快速开始

下面演示三个子模块的常用操作, 其它的方法在左侧GitHub中的开源代码

进程操作示例

from memwin.xprocess import XProcess

hwnd=329884
xp = XProcess(hwnd)
h_process = xp.get_h_process()
print(f"h_process: {h_process}")

线程操作示例

from memwin.xthread import XThread

hwnd=329884
xt = XThread(hwnd)
h_thread = xt.get_h_thread()
print(f"h_thread: {h_thread}")

内存读写操作示例

from memwin.xmemory import XMemory

hwnd=329884
xm = XMemory(hwnd)
teb_addr = xm.get_teb_addr()
print(f"TEB地址: {teb_addr}")
stack_top_addr = xm.read_int(teb_addr, 0x4)
print(f"栈顶指针: {stack_top_addr}")

单元测试

pip install pytest
pytest -s

上传分发包

第一次运行要装:

python3 -m pip install --user --upgrade setuptools wheel
pip install twine

以后运行这两个命令就可以打包和上传到PYPI了

python setup.py sdist build
twine upload dist/*

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

memwin-1.1.0.tar.gz (7.3 kB view details)

Uploaded Source

File details

Details for the file memwin-1.1.0.tar.gz.

File metadata

  • Download URL: memwin-1.1.0.tar.gz
  • Upload date:
  • Size: 7.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/5.1.1 CPython/3.8.10

File hashes

Hashes for memwin-1.1.0.tar.gz
Algorithm Hash digest
SHA256 234a5a263c55ee7bfc686d9dd71abce2a685a0baa59a32174c3af729ae1544d3
MD5 140c4ad487a8c88e7acb01afa185abed
BLAKE2b-256 f1f003587f94b4efb9dde1fbd19493dfc6f991ca1b1d4e8d0024d1361b5c1de2

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page