Skip to main content
Requires the memory permission in your manifest:
The Memory module gives scripts access to the process address space. Use it to find a module’s base address, scan for signatures, and create Pointer values to navigate from there.
ptr(addr) is also available as a global shorthand - you don’t need to write Memory.ptr(addr) everywhere.

Overview

ptr()

Wrap any address in a Pointer.

Memory.module()

Resolve a loaded module to its base address and size.

Memory.scan()

Find the first occurrence of a byte pattern in a module.

Memory.scanAll()

Collect every occurrence of a pattern across a module.

ptr


Creates a Pointer from a raw address. The two forms are identical - ptr() is the global shorthand.

Memory.module


Looks up a loaded module by name and returns its base address and byte size. Throws if the module is not found.
Throws "Memory.module: '<name>' not found" if the module isn’t loaded. Make sure the target process has already mapped the DLL before calling this.

Memory.scan


Scans the entire module for the first occurrence of pattern and returns a Pointer to it. Returns null if not found.

Memory.scanAll


Returns an array of Pointer values - one for each occurrence of pattern in the module. Returns an empty array if none found.

Pattern syntax

Patterns are space-separated hex bytes. Use ? or ?? as wildcards to match any byte at that position.
Patterns are usually copied from a disassembler (IDA, Ghidra, x64dbg). Wildcard the bytes that change between builds - typically relative offsets, addresses, and immediate values that the linker patches at link time.

Recipes

Signature scan + relative offset resolution

A common pattern: scan for a lea/mov instruction, read the embedded relative offset, and resolve the final address.

Walk a pointer chain from a scanned base

Collect all occurrences and filter by context