Windows

LdrLibraryEx – A Lightweight x64 Library For Loading DLLs Into Memory

A small x64 library to load dll’s into memory. n the world of software development, efficient DLL loading is a crucial aspect of optimizing performance and functionality.

Enter “LdrLibraryEx,” a powerful x64 library designed to streamline the process of loading DLLs into memory.

This lightweight and versatile tool offers developers a range of features, from low dependencies and memory-based loading to advanced functionality, making it an invaluable asset for enhancing Windows application performance.

Join us as we explore the capabilities and benefits of LdrLibraryEx in this comprehensive guide.

Features

  • low dependencies & function use (only ntdll.dll used)
  • position independent code
  • lightweight and minimal
  • easy to use
  • load modules from memory
  • load modules from disk
  • api sets support
  • bypass image load callbacks (using private memory)
  • support for images with delayed import, tls, seh, etc.

Documentation

Library Flags

Flags can be combined

LIBRARYEX_NONE: Map module from disk into memory and execute entrypoint.

LIBRARYEX_BYPASS_LOAD_CALLBACK: Map module from disk into private memory (unbacked) which bypasses image load callbacks (PsSetLoadImageNotifyRoutine)

LIBRARYEX_NO_ENTRY: Do not execute the entrypoint of the module.

LIBRARYEX_BUFFER: Map the module from memory instead from disk.

Function: LdrLibrary

Easy to use function to load a library into memory. The first param, based on what flags has been specified, can be either a wide string module name to load or memory address where the PE is located at.

/*!
 * @brief
 *  load library into memory
 *
 * @param Buffer
 *  buffer context to load library
 *  either a wide string or a buffer pointer 
 *  the to PE file to map (LIBRARYEX_BUFFER)
 *
 * @param Library
 *  loaded library pointer
 *
 * @param Flags
 *  flags
 *
 * @return
 *  status of function
 */NTSTATUS LdrLibrary(
    _In_  PVOID  Buffer,
    _Out_ PVOID* Library,
    _In_  ULONG  Flags
);

This example shows how to load a module from disk (from the System32 path):

PVOID Module = { 0 };
ULONG Flags  = { 0 };

//
// mapping flags to be used by the library
//
Flags = LIBRARYEX_NONE; 

//
// map file into memory
//
if ( ! NT_SUCCESS( Status = LdrLibrary( L"advapi32.dll", &Module, Flags ) ) ) {
    printf( "[-] LdrLibraryEx Failed: %p\n", Status );
    return; 
}

printf( "[*] Module @ %p\n", Module );

This examples shows how to load a module from a memory buffer:

PVOID Module = { 0 };
ULONG Flags  = { 0 };

//
// mapping flags to be used by the library
//
Flags = LIBRARYEX_NONE  | 
        LIBRARYEX_BUFFER; 

//
// read file on disk into memory
//
if ( ! ( Image = ReadFileBuffer( L"C:\\Windows\\System32\\advapi32.dll", NULL ) ) ) {
    puts( "[-] ReadFileBuffer Failed" );
    return;
}

//
// map file into memory
//
if ( ! NT_SUCCESS( Status = LdrLibrary( Image, &Module, Flags ) ) ) {
    printf( "[-] LdrLibraryEx Failed: %p\n", Status );
    return;
}

printf( "[*] Module @ %p\n", Module );

It is also possible to load modules based on their api set (win10+ support only):

//
// map file into memory
//
if ( ! NT_SUCCESS( Status = LdrLibrary( L"api-ms-win-base-util-l1-1-0.dll", &Module, Flags ) ) ) {
    printf( "[-] LdrLibraryEx Failed: %p\n", Status );
    return;
}

printf( "[*] Module @ %p\n",  );

Function: LdrLibraryEx

LdrLibraryEx allows to hook certain functions to modify the behaviour of how a library should be mapped into memory.

//
// mapping flags to be used by the library
// and insert the loaded module into Peb
//
Flags = LIBRARYEX_BYPASS_LOAD_CALLBACK |
        LIBRARYEX_NO_ENTRY;

//
// init LibraryEx context
//
if ( ! NT_SUCCESS( Status = LdrLibraryCtx( &Ctx, Flags ) ) ) {
    printf( "[-] LdrLibraryCtx Failed: %d\n", Status );
    goto END;
}

//
// hook function
//
Ctx.LdrLoadDll = C_PTR( HookLdrLoadDll );

//
// map file into memory
//
if ( ! NT_SUCCESS( Status = LdrLibraryEx( &Ctx, L"cryptsp.dll", &Module, Flags ) ) ) {
    printf( "[-] LdrLibraryEx Failed: %p\n", Status );
    return; 
}

Varshini

Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Recent Posts

Install PHP on Ubuntu 26.04: Apache, Nginx, and Multiple Versions

PHP 8.5 is included in Ubuntu 26.04's default repositories and is the recommended version for…

20 hours ago

Upgrade to Ubuntu 26.04 from 25.10 and 24.04 LTS: Complete Guide

Ubuntu 26.04 LTS "Resolute Raccoon" arrived on April 23, 2026 with Linux kernel 7.0, GNOME 50,…

20 hours ago

Install Kubernetes on Ubuntu 26.04 with kubeadm and containerd

Kubernetes is the standard platform for running containerized workloads across multiple servers with self-healing, rolling…

20 hours ago

Install Ubuntu 26.04: Bootable USB, Partitioning, and First Steps

Ubuntu 26.04 LTS "Resolute Raccoon" was released on April 23, 2026 with Linux kernel 7.0, GNOME desktop, and standard security support until April 2031. A clean install gives you a known-good starting point on new hardware, when replacing another operating system, or when an upgrade path is not practical. This guide walks through how to install Ubuntu 26.04: downloading and verifying the ISO, writing a bootable USB drive, completing the installer, and doing the initial setup after the first boot. Before you start: You need a USB drive with at least 12 GB of free space. Back up any existing data on the target machine — the installer can erase the entire disk. Install Ubuntu 26.04: Download the ISO…

20 hours ago

Change Timezone on Ubuntu: timedatectl and Desktop GUI Guide

The correct timezone affects more than the clock on your screen. It drives cron job scheduling, systemd timer execution, log file timestamps, database record timing, and SSL certificate validity checks. A mismatched timezone can cause scheduled jobs to fire at the wrong hour and make log timestamps impossible to match with real-world events. This guide shows how to change timezone on Ubuntu using the timedatectl command (the recommended approach for servers and remote machines) and through the graphical Date & Time settings on desktop systems. The steps apply to all current Ubuntu releases including 24.04 and 26.04. <strong>Prerequisite:</strong>&nbsp;Only&nbsp;the&nbsp;root&nbsp;user&nbsp;or&nbsp;a&nbsp;user&nbsp;with&nbsp;sudo&nbsp;access&nbsp;can&nbsp;change&nbsp;the&nbsp;system&nbsp;timezone. Check the Current Timezone Before You Change It Run timedatectl with no arguments to see the active timezone and clock status: bashtimedatectl Sample output: Local…

20 hours ago

Install Atom on Ubuntu 18.04: GitHub’s Code Editor APT Setup

Atom is a free, open-source, cross-platform code editor developed by GitHub. Built on Electron, it uses…

1 day ago