Bumps [eslint](https://github.com/eslint/eslint) from 9.25.0 to 9.25.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/eslint/eslint/releases">eslint's releases</a>.</em></p> <blockquote> <h2>v9.25.1</h2> <h2>Bug Fixes</h2> <ul> <li><a href="cdc8e8c950"><code>cdc8e8c</code></a> fix: revert directive detection in no-unused-expressions (<a href="https://redirect.github.com/eslint/eslint/issues/19639">#19639</a>) (sethamus)</li> </ul> <h2>Chores</h2> <ul> <li><a href="1f2b057ddc"><code>1f2b057</code></a> chore: upgrade <code>@eslint/js</code><a href="https://github.com/9"><code>@9</code></a>.25.1 (<a href="https://redirect.github.com/eslint/eslint/issues/19642">#19642</a>) (Milos Djermanovic)</li> <li><a href="771317fa93"><code>771317f</code></a> chore: package.json update for <code>@eslint/js</code> release (Jenkins)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/eslint/eslint/blob/main/CHANGELOG.md">eslint's changelog</a>.</em></p> <blockquote> <p>v9.25.1 - April 21, 2025</p> <ul> <li><a href="1f2b057ddc"><code>1f2b057</code></a> chore: upgrade <code>@eslint/js</code><a href="https://github.com/9"><code>@9</code></a>.25.1 (<a href="https://redirect.github.com/eslint/eslint/issues/19642">#19642</a>) (Milos Djermanovic)</li> <li><a href="771317fa93"><code>771317f</code></a> chore: package.json update for <code>@eslint/js</code> release (Jenkins)</li> <li><a href="cdc8e8c950"><code>cdc8e8c</code></a> fix: revert directive detection in no-unused-expressions (<a href="https://redirect.github.com/eslint/eslint/issues/19639">#19639</a>) (sethamus)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="3ed4b3652d"><code>3ed4b36</code></a> 9.25.1</li> <li><a href="7a19ccd052"><code>7a19ccd</code></a> Build: changelog update for 9.25.1</li> <li><a href="1f2b057ddc"><code>1f2b057</code></a> chore: upgrade <code>@eslint/js</code><a href="https://github.com/9"><code>@9</code></a>.25.1 (<a href="https://redirect.github.com/eslint/eslint/issues/19642">#19642</a>)</li> <li><a href="771317fa93"><code>771317f</code></a> chore: package.json update for <code>@eslint/js</code> release</li> <li><a href="cdc8e8c950"><code>cdc8e8c</code></a> fix: revert directive detection in no-unused-expressions (<a href="https://redirect.github.com/eslint/eslint/issues/19639">#19639</a>)</li> <li>See full diff in <a href="https://github.com/eslint/eslint/compare/v9.25.0...v9.25.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details>
Windows User Space Emulator
A high-performance Windows process emulator that operates at syscall level, providing full control over process execution through comprehensive hooking capabilities.
Perfect for security research, malware analysis, and DRM research where fine-grained control over process execution is required.
Built in C++ and powered by the Unicorn Engine (or the icicle-emu 🆕).
Key Features
- 🔄 Syscall-Level Emulation
- Instead of reimplementing Windows APIs, the emulator operates at the syscall level, allowing it to leverage existing system DLLs
- 📝 Advanced Memory Management
- Supports Windows-specific memory types including reserved, committed, built on top of Unicorn's memory management
- 📦 Complete PE Loading
- Handles executable and DLL loading with proper memory mapping, relocations, and TLS
- ⚡ Exception Handling
- Implements Windows structured exception handling (SEH) with proper exception dispatcher and unwinding support
- 🧵 Threading Support
- Provides a scheduled (round-robin) threading model
- 💾 State Management
- Supports both full state serialization and
fast in-memory snapshots(currently broken 😕)
- Supports both full state serialization and
- 💻 Debugging Interface
- Implements GDB serial protocol for integration with common debugging tools (IDA Pro, GDB, LLDB, VS Code, ...)
Note
The project is still in a very early, prototypical state. The code still needs a lot of cleanup and many features and syscalls need to be implemented. However, constant progress is being made :)
Preview
YouTube Overview
Click here for the slides.
Quick Start (Windows + Visual Studio)
Tip
Checkout the Wiki for more details on how to build & run the emulator on Windows, Linux, macOS, ...
1. Checkout the code:
git clone --recurse-submodules https://github.com/momo5502/emulator.git
2. Run the following command in an x64 Development Command Prompt in the cloned directory:
cmake --preset=vs2022
3. Build the solution that was generated at build/vs2022/emulator.sln
4. Create a registry dump by running the grab-registry.bat as administrator and place it in the artifacts folder next to the analyzer.exe
5. Run the program of your choice:
analyzer.exe C:\example.exe

