Skip to content

Instantly share code, notes, and snippets.

Last active November 6, 2021 15:08
Show Gist options
  • Save AddaxSoft/31ddde42d862a3fe4195645a1c91b2a5 to your computer and use it in GitHub Desktop.
Save AddaxSoft/31ddde42d862a3fe4195645a1c91b2a5 to your computer and use it in GitHub Desktop.
calling Win API from memory completely fileless
function getDelegateType {
Param (
[Parameter(Position = 0, Mandatory = $True)] [Type[]] $func,
[Parameter(Position = 1)] [Type] $functionDelegateTypeType = [Void]
$type = [AppDomain]::CurrentDomain.
DefineDynamicAssembly((New-Object System.Reflection.AssemblyName('ReflectedDelegate')),
DefineDynamicModule('InMemoryModule', $false).
DefineType('MyDelegateType', 'Class, Public, Sealed, AnsiClass, AutoClass',
$type.DefineConstructor('RTSpecialName, HideBySig, Public',
[System.Reflection.CallingConventions]::Standard, $func).
SetImplementationFlags('Runtime, Managed')
$type.DefineMethod('Invoke', 'Public, HideBySig, NewSlot, Virtual', $functionDelegateTypeType, $func).
SetImplementationFlags('Runtime, Managed')
return $type.CreateType()
function Get-ProcAddress {
Param (
    [Parameter(Position = 0, Mandatory = $True)] [String] $Module,
    [Parameter(Position = 1, Mandatory = $True)] [String] $Procedure
    # Get a reference to System.dll in the GAC
    $SystemAssembly = ([AppDomain]::CurrentDomain.GetAssemblies() |
        Where-Object { $_.GlobalAssemblyCache -And $_.Location.Split('\\')[-1].Equals('System.dll') })
    $UnsafeNativeMethods = $SystemAssembly.GetType('Microsoft.Win32.UnsafeNativeMethods')
    # Get a reference to the GetModuleHandle and GetProcAddress methods
    $GetModuleHandle = $UnsafeNativeMethods.GetMethod('GetModuleHandle')
    $UnsafeNativeMethods.GetMethods() | ForEach-Object {If($_.Name -eq "GetProcAddress") {$GetProcAddress=$_}}
    # Get a handle to the module specified
    $Kern32Handle = $GetModuleHandle.Invoke($null, @($Module))
    $tmpPtr = New-Object IntPtr
    $HandleRef = New-Object System.Runtime.InteropServices.HandleRef($tmpPtr, $Kern32Handle)
    # Return the address of the function
return $GetProcAddress.Invoke($null, @([System.Runtime.InteropServices.HandleRef]$HandleRef, $Procedure))
$functionDelegateType = getDelegateType @([IntPtr], [String], [String], [int]) ([int]) #change types as per API function paramters
$msgBoxAddr = Get-ProcAddress user32.dll MessageBoxA
$MyFunction = [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($msgBoxAddr, $functionDelegateType)
$MyFunction.Invoke([IntPtr]::Zero,"1337","twitter: @xxByte",0)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment