Files
whitemagic/openspec/changes/inject-and-assemble/proposal.md
T
2026-07-21 22:30:10 +02:00

1.7 KiB

Why

BlackMagic replaced FASM for code-payload generation but lost two useful capabilities:

  1. Non-blocking remote execution (InjectAndExecuteEx): FASM's managed wrapper returned a thread handle without waiting. BlackMagic only has blocking Execute(). For DLL injection, a non-blocking variant avoids hanging when the target is slow to load.

  2. Text-based assembly: FASM allowed building code payloads from assembly text (AddLine("pushad")). BlackMagic requires hand-assembled byte[]. For prototyping, debugging, and one-off code payloads, text assembly is faster to write and easier to review. A managed assembler eliminates the native FASM DLL dependency while keeping the ergonomic benefit.

What Changes

  • Add InjectAndExecuteEx() to BlackMagic and BMThread: inject code then create a remote thread without waiting, returning the thread handle.
  • Add AsmBuilder class: pure C# x86 text assembler that converts instruction text to byte[] machine code. Supports common payload instructions (mov, push, pop, call, jmp, ret, nop, pushad/popad, test, je, jne, inc, add, sub, xor, etc.).
  • Add InjectAndExecute(string asm) and InjectAndExecuteEx(string asm) overloads that accept assembly text, assemble via AsmBuilder, then inject+execute.
  • Add SetPassLimit() to AsmBuilder for label resolution iteration control.

Capabilities

New Capabilities

  • non-blocking-execute: Non-blocking remote thread creation that returns a handle without waiting for exit.
  • text-assembler: Pure C# x86 text assembler converting assembly source to byte arrays without native dependencies.

Modified Capabilities