Memory Mapper is a lightweight library which allows the ability to map both native and managed assemblies into memory by either using process injection of a process specified by the user or self-injection; the technique of injecting an assembly into the currently running process attempting to do the injection.
The library comes with tools not only to map assemblies, but with the capabilities to encrypt, decrypt, and generate various amounts of cryptographically strong data.
Requirements
Note: (For the running assembly using Memory Mapper ONLY — not for stubs/shellcode)
Features
SecureRandom
objectAlso Read – Faraday : Collaborative Penetration Test & Vulnerability Management Platform
Examples
This example shows how to statically map a native assembly into memory using the NativeLoader
tool. The example loads the file by reading all of its bytes from disk and then injects the PE (portable executable) associated with the bytes directly into memory. Using the native loader in conjunction with Dynamic Code Compilation found in my Amaterasu library one could accomplish on-the-fly code compilation and injection all from code in-memory.
using System;
using System.IO;
using System.Reflection;
using MemoryMapper;
namespace Example
{
class Program
{
static void Main(string[].args)
{
// Get the bytes of the file we want to load.
var filePath = “FileToReadBytesOf”;
var fileBytes = File.ReadAllBytes(filePath);
// Check if the assembly is managed or native.
bool isManaged = false;
try
{
// Note — this is one of the simplest variations of checking assemblies
var assemblyName = AssemblyName.GetAssemblyName(filePath);
if (assemblyName != null)
if (assemblyName.FullName != null)
isManaged = true;
}
catch { isManaged = false; }
// Try loading the assembly if it’s truly native.
if (!isManaged)
{
NativeLoader loader = new NativeLoader();
if (loader.LoadAssembly(fileBytes))
Console.WriteLine(“Assembly loaded successfully!”);
else
Console.WriteLine(“Assembly could not be loaded.”);
}
// Wait for user interaction.
Console.Read();
}
}
}
Managed Injection
This example shows how to statically map a managed assembly into memory by reading in its bytes — or by using an embedded byte array — and then using the ManagedLoader to inject into a currently running process. Almost any managed assembly can be mapped using the provided ManagedLoader tool.
using System;
using System.IO;
using System.Reflection;
using MemoryMapper;
namespace Example
{
class Program
{
static void Main(string[] args)
{
// Get the bytes of the file we want to load.
var filePath = “FileToReadBytesOf”;
var fileBytes = File.ReadAllBytes(filePath);
// Check if the assembly is managed or native.
bool isManaged = false;
try
{
// Note — this is one of the simplest variations of checking assemblies
var assemblyName = AssemblyName.GetAssemblyName(filePath);
if (assemblyName != null)
if (assemblyName.FullName != null)
isManaged = true;
}
catch { isManaged = false; }
// Try loading the assembly if it’s truly managed.
if (isManaged)
{
// Set the name of a surrogate process – the process we’ll inject into.
var processName = “explorer.exe”; // Can also be the current process’s name for self-injection.
ManagedLoader loader = new ManagedLoader();
if (loader.LoadAssembly(fileBytes, processName))
Console.WriteLine(“Assembly loaded successfully!”);
else
Console.WriteLine(“Assembly could not be loaded.”);
}
// Wait for user interaction.
Console.Read();
}
}
}
Disclaimer
THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
shadow-rs is a Windows kernel rootkit written in Rust, demonstrating advanced techniques for kernel manipulation…
Extract and execute a PE embedded within a PNG file using an LNK file. The…
Embark on the journey of becoming a certified Red Team professional with our definitive guide.…
This repository contains proof of concept exploits for CVE-2024-5836 and CVE-2024-6778, which are vulnerabilities within…
This took me like 4 days (+2 days for an update), but I got it…
MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection. Its foundation is…