Struct NativeMethodMatcher
pub struct NativeMethodMatcher { /* private fields */ }Expand description
Matches P/Invoke (native) method calls by DLL name and/or function name.
This matcher identifies calls to unmanaged code through the P/Invoke mechanism. It can match by DLL name, function name, or both.
§Normalization
DLL names are normalized to lowercase and the .dll extension is removed
for consistent matching. Function names are compared case-sensitively.
§Examples
use dotscope::emulation::NativeMethodMatcher;
// Match all calls to kernel32.dll
let matcher = NativeMethodMatcher::new().dll("kernel32");
// Match VirtualProtect specifically
let matcher = NativeMethodMatcher::full("kernel32", "VirtualProtect");
// Match any function named GetModuleHandle (any DLL)
let matcher = NativeMethodMatcher::new().function("GetModuleHandle");Implementations§
§impl NativeMethodMatcher
impl NativeMethodMatcher
pub fn new() -> Self
pub fn new() -> Self
Creates a new native method matcher with no constraints.
Use the builder methods to specify which components to match.
pub fn dll(self, dll: impl Into<String>) -> Self
pub fn dll(self, dll: impl Into<String>) -> Self
Sets the DLL name to match.
The DLL name is normalized: converted to lowercase with .dll extension removed.
§Arguments
dll- The DLL name to match (e.g., “kernel32” or “kernel32.dll”)
pub fn function(self, function: impl Into<String>) -> Self
pub fn function(self, function: impl Into<String>) -> Self
Sets the function name to match.
Function names are matched case-sensitively.
§Arguments
function- The function name to match (e.g., “VirtualProtect”)
Trait Implementations§
§impl Clone for NativeMethodMatcher
impl Clone for NativeMethodMatcher
§fn clone(&self) -> NativeMethodMatcher
fn clone(&self) -> NativeMethodMatcher
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read more§impl Debug for NativeMethodMatcher
impl Debug for NativeMethodMatcher
§impl Default for NativeMethodMatcher
impl Default for NativeMethodMatcher
§fn default() -> NativeMethodMatcher
fn default() -> NativeMethodMatcher
Returns the “default value” for a type. Read more
§impl HookMatcher for NativeMethodMatcher
impl HookMatcher for NativeMethodMatcher
§fn matches(&self, context: &HookContext<'_>, _thread: &EmulationThread) -> bool
fn matches(&self, context: &HookContext<'_>, _thread: &EmulationThread) -> bool
Checks if this matcher matches the given context. Read more
§fn description(&self) -> String
fn description(&self) -> String
Returns a description of this matcher for debugging. Read more
§fn name_components(&self) -> Option<(Option<&str>, Option<&str>, Option<&str>)>
fn name_components(&self) -> Option<(Option<&str>, Option<&str>, Option<&str>)>
Returns the name components if this is a name-based matcher. Read more
§fn is_runtime_matcher(&self) -> bool
fn is_runtime_matcher(&self) -> bool
Returns
true if this matcher requires runtime argument inspection. Read more§fn is_signature_matcher(&self) -> bool
fn is_signature_matcher(&self) -> bool
Returns
true if this matcher requires method signature information. Read moreAuto Trait Implementations§
impl Freeze for NativeMethodMatcher
impl RefUnwindSafe for NativeMethodMatcher
impl Send for NativeMethodMatcher
impl Sync for NativeMethodMatcher
impl Unpin for NativeMethodMatcher
impl UnsafeUnpin for NativeMethodMatcher
impl UnwindSafe for NativeMethodMatcher
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Downcast for T
impl<T> Downcast for T
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<F, T> IntoSample<T> for Fwhere
T: FromSample<F>,
impl<F, T> IntoSample<T> for Fwhere
T: FromSample<F>,
fn into_sample(self) -> T
Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<R, P> ReadPrimitive<R> for P
impl<R, P> ReadPrimitive<R> for P
Source§fn read_from_little_endian(read: &mut R) -> Result<Self, Error>
fn read_from_little_endian(read: &mut R) -> Result<Self, Error>
Read this value from the supplied reader. Same as
ReadEndian::read_from_little_endian().Source§impl<SS, SP> SupersetOf<SS> for SPwhere
SS: SubsetOf<SP>,
impl<SS, SP> SupersetOf<SS> for SPwhere
SS: SubsetOf<SP>,
Source§fn to_subset(&self) -> Option<SS>
fn to_subset(&self) -> Option<SS>
The inverse inclusion map: attempts to construct
self from the equivalent element of its
superset. Read moreSource§fn is_in_subset(&self) -> bool
fn is_in_subset(&self) -> bool
Checks if
self is actually part of its subset T (and can be converted to it).Source§fn to_subset_unchecked(&self) -> SS
fn to_subset_unchecked(&self) -> SS
Use with care! Same as
self.to_subset but without any property checks. Always succeeds.Source§fn from_subset(element: &SS) -> SP
fn from_subset(element: &SS) -> SP
The inclusion map: converts
self to the equivalent element of its superset.