#[inline(always)]
pub fn is_single_reg(instr: &zydis::DecodedInstruction) -> bool {
let regs_read_cnt = instr.operands.iter().filter(|&o| {
(o.action == zydis::enums::OperandAction::READ)
&& (o.ty == zydis::enums::OperandType::REGISTER)
}).count();
regs_read_cnt == 1
}
#[inline(always)]
pub fn is_single_reg_deref(instr: &zydis::DecodedInstruction) -> bool {
let regs_deref_cnt = instr.operands.iter().filter(|&o| {
(o.action == zydis::enums::OperandAction::READ)
&& (o.ty == zydis::enums::OperandType::MEMORY)
&& (o.mem.base != zydis::Register::NONE)
}).count();
regs_deref_cnt == 1
}
#[inline(always)]
pub fn is_reg_set_call(instr: &zydis::DecodedInstruction) -> bool {
is_call(&instr)
&& is_single_reg(&instr)
}
#[inline(always)]
pub fn is_reg_set_jmp(instr: &zydis::DecodedInstruction) -> bool {
is_jmp(&instr)
&& is_single_reg(&instr)
}
#[inline(always)]
pub fn is_mem_ptr_set_jmp(instr: &zydis::DecodedInstruction) -> bool {
is_jmp(&instr)
&& is_single_reg_deref(&instr)
}
#[inline(always)]
pub fn is_mem_ptr_set_call(instr: &zydis::DecodedInstruction) -> bool {
is_call(&instr)
&& is_single_reg_deref(&instr)
}
#[inline(always)]
pub fn is_gadget_tail(instr: &zydis::DecodedInstruction) -> bool {
is_ret(instr)
|| is_jop_gadget_tail(instr)
|| is_sys_gadget_tail(instr)
}
#[inline(always)]
pub fn is_jop_gadget_tail(instr: &zydis::DecodedInstruction) -> bool {
is_reg_set_jmp(instr)
|| is_reg_set_call(instr)
|| is_mem_ptr_set_jmp(instr)
|| is_mem_ptr_set_call(instr)
}
#[inline(always)]
pub fn is_sys_gadget_tail(instr: &zydis::DecodedInstruction) -> bool {
is_syscall(instr)
|| is_linux_syscall(instr)
}
#[inline(always)]
pub fn is_ret(instr: &zydis::DecodedInstruction) -> bool {
instr.meta.category == zydis::enums::InstructionCategory::RET
}
#[inline(always)]
pub fn is_call(instr: &zydis::DecodedInstruction) -> bool {
instr.meta.category == zydis::enums::InstructionCategory::CALL
}
pub fn is_jmp(instr: &zydis::DecodedInstruction) -> bool {
instr.mnemonic == zydis::enums::Mnemonic::JMP
}
#[inline(always)]
pub fn is_int(instr: &zydis::DecodedInstruction) -> bool {
instr.meta.category == zydis::enums::InstructionCategory::INTERRUPT
}
#[inline(always)]
pub fn is_syscall(instr: &zydis::DecodedInstruction) -> bool {
instr.meta.category == zydis::enums::InstructionCategory::SYSCALL
}
#[inline(always)]
pub fn is_linux_syscall(instr: &zydis::DecodedInstruction) -> bool {
let imm_0x80_cnt = instr.operands.iter().filter(|&o| {
(o.action == zydis::enums::OperandAction::READ)
&& (o.ty == zydis::enums::OperandType::IMMEDIATE)
&& (o.imm.value == 0x80)
}).count();
(instr.meta.category == zydis::enums::InstructionCategory::INTERRUPT)
&& (imm_0x80_cnt == 1)
}