Skip to main content
Version: 15.x (API 15) [Current]

Class SigScanner

A SigScanner facilitates searching for memory signatures in a given ProcessModule.

Assembly: Dalamud.dll​
Declaration
public class SigScanner : IDisposable, ISigScanner, IDalamudService

Implements:
System.IDisposable, Dalamud.Plugin.Services.ISigScanner, Dalamud.Plugin.Services.IDalamudService

Properties​

IsCopy​

Gets a value indicating whether the search on this module is performed on a copy.

Declaration
public bool IsCopy { get; }

SearchBase​

Gets the base address of the search area. When copied, this will be the address of the copy.

Declaration
public nint SearchBase { get; }

TextSectionBase​

Gets the base address of the .text section search area.

Declaration
public nint TextSectionBase { get; }

TextSectionOffset​

Gets the offset of the .text section from the base of the module.

Declaration
public long TextSectionOffset { get; }

TextSectionSize​

Gets the size of the text section.

Declaration
public int TextSectionSize { get; }

DataSectionBase​

Gets the base address of the .data section search area.

Declaration
public nint DataSectionBase { get; }

DataSectionOffset​

Gets the offset of the .data section from the base of the module.

Declaration
public long DataSectionOffset { get; }

DataSectionSize​

Gets the size of the .data section.

Declaration
public int DataSectionSize { get; }

RDataSectionBase​

Gets the base address of the .rdata section search area.

Declaration
public nint RDataSectionBase { get; }

RDataSectionOffset​

Gets the offset of the .rdata section from the base of the module.

Declaration
public long RDataSectionOffset { get; }

RDataSectionSize​

Gets the size of the .rdata section.

Declaration
public int RDataSectionSize { get; }

Module​

Gets the ProcessModule on which the search is performed.

Declaration
public ProcessModule Module { get; }

Methods​

Scan(nint, int, string)​

Scan memory for a signature.

Declaration
public static nint Scan(nint baseAddress, int size, string signature)
Returns​

System.IntPtr: The found offset.

Parameters​
TypeNameDescription
System.IntPtrbaseAddressThe base address to scan from.
System.Int32sizeThe amount of bytes to scan.
System.StringsignatureThe signature to search for.

TryScan(nint, int, string, out nint)​

Try scanning memory for a signature.

Declaration
public static bool TryScan(nint baseAddress, int size, string signature, out nint result)
Returns​

System.Boolean: true if the signature was found.

Parameters​
TypeNameDescription
System.IntPtrbaseAddressThe base address to scan from.
System.Int32sizeThe amount of bytes to scan.
System.StringsignatureThe signature to search for.
System.IntPtrresultThe offset, if found.

GetStaticAddressFromSig(string, int)​

Scan for a .data address using a .text function. This is intended to be used with IDA sigs. Place your cursor on the line calling a static address, and create and IDA sig. The signature and offset should not break through instruction boundaries.

Declaration
public nint GetStaticAddressFromSig(string signature, int offset = 0)
Returns​

System.IntPtr: An nint to the static memory location.

Parameters​
TypeNameDescription
System.StringsignatureThe signature of the function using the data.
System.Int32offsetThe offset from function start of the instruction using the data.

TryGetStaticAddressFromSig(string, out nint, int)​

Try scanning for a .data address using a .text function. This is intended to be used with IDA sigs. Place your cursor on the line calling a static address, and create and IDA sig.

Declaration
public bool TryGetStaticAddressFromSig(string signature, out nint result, int offset = 0)
Returns​

System.Boolean: true if the signature was found.

Parameters​
TypeNameDescription
System.StringsignatureThe signature of the function using the data.
System.IntPtrresultAn nint to the static memory location, if found.
System.Int32offsetThe offset from function start of the instruction using the data.

ScanData(string)​

Scan for a byte signature in the .data section.

Declaration
public nint ScanData(string signature)
Returns​

System.IntPtr: The real offset of the found signature.

Parameters​
TypeNameDescription
System.StringsignatureThe signature.

TryScanData(string, out nint)​

Try scanning for a byte signature in the .data section.

Declaration
public bool TryScanData(string signature, out nint result)
Returns​

System.Boolean: true if the signature was found.

Parameters​
TypeNameDescription
System.StringsignatureThe signature.
System.IntPtrresultThe real offset of the signature, if found.

ScanModule(string)​

Scan for a byte signature in the whole module search area.

Declaration
public nint ScanModule(string signature)
Returns​

System.IntPtr: The real offset of the found signature.

Parameters​
TypeNameDescription
System.StringsignatureThe signature.

TryScanModule(string, out nint)​

Try scanning for a byte signature in the whole module search area.

Declaration
public bool TryScanModule(string signature, out nint result)
Returns​

System.Boolean: true if the signature was found.

Parameters​
TypeNameDescription
System.StringsignatureThe signature.
System.IntPtrresultThe real offset of the signature, if found.

ResolveRelativeAddress(nint, int)​

Resolve a RVA address.

Declaration
public nint ResolveRelativeAddress(nint nextInstAddr, int relOffset)
Returns​

System.IntPtr: The calculated offset.

Parameters​
TypeNameDescription
System.IntPtrnextInstAddrThe address of the next instruction.
System.Int32relOffsetThe relative offset.

ScanText(string)​

Scan for a byte signature in the .text section.

Declaration
public nint ScanText(string signature)
Returns​

System.IntPtr: The real offset of the found signature.

Parameters​
TypeNameDescription
System.StringsignatureThe signature.

TryScanText(string, out nint)​

Try scanning for a byte signature in the .text section.

Declaration
public bool TryScanText(string signature, out nint result)
Returns​

System.Boolean: true if the signature was found.

Parameters​
TypeNameDescription
System.StringsignatureThe signature.
System.IntPtrresultThe real offset of the signature, if found.

ScanAllText(string)​

Scan for all matching byte signatures in the .text section.

Declaration
public nint[] ScanAllText(string signature)
Returns​

System.IntPtr[]: The list of real offsets of the found elements based on signature.

Parameters​
TypeNameDescription
System.StringsignatureThe Signature.

ScanAllText(string, CancellationToken)​

Scan for all matching byte signatures in the .text section.

Declaration
public IEnumerable<nint> ScanAllText(string signature, CancellationToken cancellationToken)
Returns​

System.Collections.Generic.IEnumerable<System.IntPtr>: Enumerable yielding the real offsets of the found elements based on signature.

Parameters​
TypeNameDescription
System.StringsignatureThe Signature.
System.Threading.CancellationTokencancellationTokenCancellation token.

Dispose()​

Declaration
public void Dispose()

Implements​