tobiohlala / psmemory Goto Github PK
View Code? Open in Web Editor NEWAutomation Capable Multi Search 64 Bit Windows Memory Scanner
Home Page: https://www.powershellgallery.com/packages/PSMemory
License: BSD 3-Clause "New" or "Revised" License
Automation Capable Multi Search 64 Bit Windows Memory Scanner
Home Page: https://www.powershellgallery.com/packages/PSMemory
License: BSD 3-Clause "New" or "Revised" License
Hello, Thank you for your work on this project, it is very interesting. I am using it to do a research project where I am using PowerShell to read process memory. Would it be possible for you to provide an example command using the Bytes parameter? I have tried a few and can't seem to get it to search for Unicode bytes. Thanks!
Name Value
---- -----
PSVersion 5.1.17763.503
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.17763.503
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
This is my powershell environment.
Unable to find type [PSMemory.Native].
At C:\Program Files\WindowsPowerShell\Modules\PSMemory\1.0.0\PSMemory.psm1:215 char:27
+ if (($processHandle = [PSMemory.Native]::OpenProcess(
+ ~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (PSMemory.Native:TypeName) [], RuntimeException
+ FullyQualifiedErrorId : TypeNotFound
New-Object : Cannot find type [PSMemory.Native+SYSTEM_INFO]: verify that the assembly containing this type is loaded.
At C:\Program Files\WindowsPowerShell\Modules\PSMemory\1.0.0\PSMemory.psm1:224 char:19
+ $systemInfo = New-Object PSMemory.Native+SYSTEM_INFO
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidType: (:) [New-Object], PSArgumentException
+ FullyQualifiedErrorId : TypeNotFound,Microsoft.PowerShell.Commands.NewObjectCommand
Unable to find type [PSMemory.Native].
At C:\Program Files\WindowsPowerShell\Modules\PSMemory\1.0.0\PSMemory.psm1:225 char:5
+ [PSMemory.Native]::GetNativeSystemInfo([ref]$systemInfo)
+ ~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (PSMemory.Native:TypeName) [], RuntimeException
+ FullyQualifiedErrorId : TypeNotFound
New-Object : Cannot find type [PSMemory.Native+MEMORY_BASIC_INFORMATION64]: verify that the assembly containing this
type is loaded.
At C:\Program Files\WindowsPowerShell\Modules\PSMemory\1.0.0\PSMemory.psm1:229 char:19
+ ... $memoryInfo = New-Object PSMemory.Native+MEMORY_BASIC_INFORMATION64
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidType: (:) [New-Object], PSArgumentException
+ FullyQualifiedErrorId : TypeNotFound,Microsoft.PowerShell.Commands.NewObjectCommand
Exception calling "SizeOf" with "1" argument(s): "Value cannot be null.
Parameter name: structure"
At C:\Program Files\WindowsPowerShell\Modules\PSMemory\1.0.0\PSMemory.psm1:230 char:5
+ $memoryInfoSize = [Runtime.InteropServices.Marshal]::SizeOf($memo ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [], MethodInvocationException
+ FullyQualifiedErrorId : ArgumentNullException
Unable to find type [PSMemory.Native].
At C:\Program Files\WindowsPowerShell\Modules\PSMemory\1.0.0\PSMemory.psm1:330 char:12
+ [void] [PSMemory.Native]::CloseHandle($processHandle)
+ ~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (PSMemory.Native:TypeName) [], RuntimeException
+ FullyQualifiedErrorId : TypeNotFound
I've got this error message when I trying a script below:
Get-Process notepad | Search-Memory -Values @{
Int = 1234, 5678
String = 'Notepad'
} -OutVariable notepad
Of course, I executed notepad.exe at the time.
what's the problem??
I installed this with Install-Module -Name PSMemory
and A(All to yes)
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.