- Written on pure C
- Extremely lightweight
- Based on the fastest and lightweight Zydis disassembler
- Uses only NativeAPI functions
- Has no other dependencies
- Kernelmode support
- Supports instructions relocation and thread's contexts fixup
- The HookLib was completely rewritten
- Extremely reduced allocations, processes/threads enumerations and handles manipulations count
- Multihook/multiunhook support that hooks/unhooks multiple functions in one session
- Extremely reduced memory consumption for usermode hooks: one hook page (4Kb) can hold 39 cells for nearest hooks that removes the need to allocate one page per each hook
- Support for KM->UM hooks (even with support for contexts fixup directly from kernelmode):
- KM:Amd64 -> UM:Amd64
- KM:Amd64 -> UM:Wow64
- KM:i386 -> UM:i386
TargetFunction(): ^ ; return
-> jmp Interceptor ------> Interceptor(): |
??? ; Broken bytes ... Handler code ... |
... ; Continuation <--+ CallOriginal() ------|--> OriginalBeginning():
... +---------|-> ... | ... Original beginning ...
ret --------+ | ret -----------------+ ... of TargetFunction ...
+------------------------------ jmp Continuation
Supported trampolines:
Jump to a relative offset:E9 44332211 | jmprip+0x11223344 ; Relative jump to ±2Gb onlyJump to anabsoluteaddress (x32):FF 2544332211 | jmpds:[0x11223344]NN NN NN NN | <-0x11223344 is points toJump to anabsoluteaddress (x64):FF 2500000000 | jmp[rip+00h]8877665544332211 | <-RIP is points toTrampolines selection logic:
if (relative_jumpable(fn, handler))
{
set_relative_jump(fn, handler);
}
else
{
/* 'Intermediate' is an intermediate buffer that allocates in the same block with the function beginning:*/if (relative_jumpable(fn, intermediate))
{
set_relative_jump(fn, intermediate);
set_absolute_jump(intermediate, handler); }
else
{
set_absolute_jump(fn, handler);
}
}Add the HookLib.vcxproj to your .sln and add the reference to the HookLib project into your project references list as described here: select project, open the project menu, click Add -> Reference and select the HookLib.
Then add ./HookLib/HookLib/ folder to your header folders list and you're good to go.
#include<HookLib.h>intfunc(int a, int b)
{
return a + b;
}
inthandler(int a, int b)
{
return a * b;
}
template <typename Fn>
Fn hookFunc(Fn fn, Fn handler)
{
returnstatic_cast<Fn>(hook(fn, handler));
}
voidtestSimpleHook()
{
constauto orig = hookFunc(func, handler);
assert(func(2, 3) == 6); // Hooked, the 'handler' will be called insteadassert(orig(2, 3) == 5);
unhook(orig);
assert(func(2, 3) == 5);
}
voidtestCppHelpers()
{
constauto holder = HookFactory::install(func, handler);
assert(func(2, 3) == 6);
assert(holder.call(2, 3) == 5);
}
intmain()
{
testSimpleHook();
testCppHelpers();
return0;
}