NativeSharp is a dynamic library designed for injection into .NET executables. Once injected, it extracts comprehensive metadata and enables JSONPath queries on classes, types, and instances, facilitating in-depth analysis and manipulation of .NET applications.
- Metadata Extraction: Retrieve detailed information about classes, methods, properties, and other components within a .NET executable.
- JSONPath Querying: Execute JSONPath queries to navigate and filter the extracted metadata efficiently, including querying live instances.
- Dynamic Injection: Seamlessly inject into running .NET applications to perform real-time analysis.
To utilize NativeSharp, follow these steps:
-
Clone the Repository:
git clone https://github.com/yourusername/NativeSharp.git
-
Build the Project:
- Open the solution in your preferred IDE.
- Build the solution to generate the
NativeSharp.dll.
-
Inject the DLL:
- Use your preferred DLL injection method to inject
NativeSharp.dllinto the target .NET executable.
- Use your preferred DLL injection method to inject
-
Execute JSONPath Queries:
- After injection, utilize the provided interfaces to perform JSONPath queries on the application's metadata.
Once injected, NativeSharp provides an interface to execute JSONPath queries. For example, to retrieve all classes with a specific attribute:
std::string query = "$..[?(@.attributes[?(@.name == 'YourAttribute')])]";Refer to the documentation for detailed usage examples and API references.
The following tasks are planned for future development:
- Implement the .NET generic Data Collector class.
- Fix the issue causing crashes related to garbage collection and thread suspension.
- Remove direct logging; instead, pass a function pointer to the collectors class for logging purposes.
- Refactor
DllMenuGuito avoid singleton implementation. - Rename
DllMenuGuitoDllGuiManagerInterfaceand define it as a purely virtual interface. - Make
NativeSharpGuiManagerderive fromDllGuiManagerInterface. - Implement the query interface for the interface data collector class.
- Abstract all the api calls (thread, EnumModule32, ..) - blackbone \ blackbone driver should be used.
Contributions are welcome! Please fork the repository and submit a pull request for any enhancements or bug fixes. Ensure that your code adheres to the project's coding standards and includes appropriate tests.
This project is licensed under the MIT License. See the LICENSE file for details.
Special thanks to all contributors and the open-source community for their invaluable support and resources.
BlackBone by DarthTon - For process memory manipulations. CheatEngine - Refrenced many times for the Mono implementation. jsoncors - Used to map structs and run advanced queries. dear ImGui - For the entire GUI.
Note: Ensure that the repository URL and any specific details are updated to reflect your actual project information.