Created by ZxPwd
Discord: zxpwd
CrxMem is a Windows memory scanner and analysis project inspired by Cheat Engine. The repository now contains the redesigned compact WPF main application, a newer WPF Memory View, the retained Legacy Memory Viewer, Auto Assembler work, bookmark tooling, Watchdog Hunter research tooling, and optional kernel-driver experiments.
Warning
CrxMem is pre-release research software. User-mode scanning is the most stable path today. Debugger, injection, anti-cheat research, and kernel-driver features remain experimental and can destabilize target processes or Windows.
The project has moved well beyond a basic scanner. The current build includes a redesigned main UI, two Memory View routes, bookmark infrastructure, Auto Assembler work, and optional driver-assisted features, but not every advanced debugging feature is fully complete yet.
| Area | Status | Notes |
|---|---|---|
| Scanner / Address List | Working, pre-release | Exact/comparison scans, undo, filters, writable-region scanning, and address-list workflows are part of the active WPF shell |
| Main WPF shell | Working, pre-release | Compact dark-blue redesign with process status, scan workspace, table workflow, and settings integration |
| Memory View (WPF) | Working, pre-release | Disassembly, hex dump, navigation, modules, memory map, patch pane, Auto Assembler entry point, and Bookmark Manager |
| Memory Viewer (Legacy) | Working, retained | Previous WinForms/GDI+ viewer remains available as a fallback and comparison route |
| Bookmarks / comments | Working, evolving | Docked Bookmark Manager, annotation persistence, edit/move/rebind/import/export paths |
| Auto Assembler | Experimental | UI and transactional script infrastructure are present, but compatibility is still incomplete |
| Debugger / breakpoints | Prototype | Attach/run-control/stepping work exists, but this is not yet a parity-complete attached debugger |
| Watchdog Hunter | Experimental research tool | Thread census and integrity-thread hunting workflows for isolated research use |
| Lua engine | Incomplete | Core pieces exist; full compatibility surface is still under development |
| CrxShield driver path | Experimental | Optional kernel-assisted operations and tooling, not covered by the managed CI build |
Tools > Memory View (WPF)opens the newer Memory View workspace.Tools > Memory Viewer (Legacy)opens the retained older viewer.- The Legacy viewer is still intentionally shipped because it remains useful while newer Memory View features continue to mature.
- Kernel and anti-cheat research features should be treated as isolated-lab functionality, not everyday-safe defaults.
This repository now includes the main application plus several experimental companion projects and research folders:
CrxMem/
|-- CrxMem/ # Main C# application (WPF shell + legacy WinForms components)
|-- CrxMem.Tests/ # Managed test suite
|-- CrxShield/ # Experimental kernel driver
|-- CrxShieldClient/ # Driver client/native interop work
|-- VEHDebugDll/ # VEH-based debugging experiments
|-- FxpStrip/ # Native anti-cheat / hook research work
|-- GunzAnalysis/ # Analysis notes, scripts, and research artifacts
`-- Documentation/ # Plans, design references, and implementation notes
| Project | Description | Language |
|---|---|---|
| CrxMem | Main GUI application for scanning, editing, analysis, Memory View, and table workflows | C# (.NET 8) |
| CrxShield | Experimental Windows kernel driver for kernel-assisted memory access and thread tooling | C / WDK |
| CrxShieldClient | Client-side driver access helpers and native interop | C++ / C# |
| VEHDebugDll | VEH-based debugging and breakpoint experiments | C++ |
| FxpStrip | Native reversing and anti-cheat research project | C++ |
| GunzAnalysis | Notes, scripts, and reverse-engineering artifacts | Mixed |
The main application now uses a dark-themed WPF shell with a compact scanner-first layout while still keeping selected legacy components where they remain useful.
- Compact redesigned main window optimized for smaller screens
- Process-aware header with runtime process status
- Scan Results and Address List in virtualized WPF DataGrids
- Built-in access to Memory View, Legacy Memory Viewer, Lua, PE analysis, Watchdog Hunter, and Settings
- Persistent layout and settings migration support
- Exact, increased, decreased, changed, unchanged, unknown, between, and AOB scan workflows
- Value types including Byte, 2/4/8 Bytes, Float, Double, String, and AOB
- Address-list editing, freezing, save/load, and manual address entry
- Versioned
.crxcttable format with legacy CrxMem.ctJSON import support
- Memory View (WPF):
- disassembly view
- hex dump
- stack/watch/breakpoints/call stack/memory map/modules/threads panes
- patch editor
- Auto Assembler entry point
- Bookmark Manager workspace
- Memory Viewer (Legacy):
- retained WinForms/GDI+ path
- useful fallback during ongoing WPF debugger and Memory View development
- Bookmark/comment annotations with manager workflow
- Auto Assembler editor and preview pipeline
- PE analysis
- Lua integration work
- Watchdog Hunter thread-analysis workflow
- Driver-aware memory operations when CrxShield is connected and enabled
- .NET 8.0
- WPF and WinForms
- Iced for x86/x64 disassembly
- NLua for Lua integration work
- ReaLTaiizor for selected UI controls
CrxShield is the repository's experimental kernel-driver track for research builds that need kernel-assisted memory access or thread tooling.
- Kernel-level read/write support
- Process base address retrieval
- Thread enumeration support used by research tooling
- Driver management and restart tooling
- Verification helpers and setup scripts under
CrxShield/Tools
Kernel drivers can cause system instability, startup failures, or BSODs. Test only on isolated systems or disposable environments.
VEHDebugDll contains vectored-exception-handler debugging experiments used for breakpoint and access-monitor research.
- Hardware breakpoint experiments
- Memory access monitoring
- Shared-memory IPC concepts
- Lock-free/event-driven debugging experiments
git clone https://github.com/ZxPwdz/CrxMem.git
cd CrxMem
dotnet restore CrxMem.sln
dotnet build CrxMem.sln -c Release --no-restoreManaged output:
CrxMem\bin\Release\net8.0-windows\
Authentication is not required to clone the public repository. Contributors should use Git Credential Manager, GitHub CLI browser login, or SSH when pushing. Never place a token in a command, remote URL, script, or committed file.
- Install the Windows Driver Kit.
- Open
CrxShield/CrxShield.vcxprojor the solution in Visual Studio 2022. - Build the driver in Release mode.
- If using test-signed builds, enable testsigning and reboot before loading the driver.
Build the Visual Studio project in the matching architecture you want to test.
- Build or download the Release version.
- Open
CrxMem\bin\Release\net8.0-windows\. - Run
CrxMem.exe.
CrxMem stores versioned settings in:
%LocalAppData%\CrxMem\settings.json
Older registry-backed settings are imported on first run when appropriate. Invalid JSON is preserved as a timestamped recovery file and replaced with safe defaults.
Driver management helpers live under:
CrxShield\Tools\
Use those scripts and commands rather than inventing a custom install flow.
- Use
File > Open Process. - Enter a value to search for.
- Choose a scan type and value type.
- Run
First Scan. - Change the value in the target.
- Run
Next Scanuntil the result set is small enough. - Add matching rows to the Address List.
- Use
Memory Viewfrom the main window for the newer WPF route. - Use
Tools > Memory Viewer (Legacy)if you want the older retained viewer.
- In the WPF Memory View, use
Ctrl+Dto toggle a bookmark on the selected instruction. - Use
;to edit comment/bookmark metadata. - Use
Ctrl+Shift+Bor the workspace button to open Bookmark Manager.
CrxMem/
|-- Core/ # Scanning, process access, driver-aware services
|-- MemoryView/ # Legacy viewer + WPF Memory View implementation
|-- MemoryView/Wpf/ # Newer Memory View views, services, and themes
|-- Legacy/ # Retained legacy shell/reference pieces
|-- LuaScripting/ # Lua integration work
|-- Themes/ # MainWindow theme resources
|-- MainWindow.xaml # Main compact WPF shell
|-- SettingsWindow.xaml # Settings UI including CrxShield tooling
`-- WatchdogHunterWindow.xaml # Watchdog Hunter research tool
Documentation/DesignReferences/holds captured visual references.Documentation/Plans/holds milestone and redesign plans.- Companion folders such as
GunzAnalysis/andFxpStrip/contain deeper research notes and experiments.
Contributions are welcome. See CONTRIBUTING.md for workflow and boundaries. Report vulnerabilities privately as described in SECURITY.md.
This software is provided for educational and security research purposes only.
- Do not use it for malicious purposes.
- Do not use it to attack online games or third-party services.
- Treat kernel and anti-cheat features as isolated research tooling.
- Always test risky features on systems you can recover.
Licensed under the MIT License.

