scan_pattern
Scan non-shared process memory for byte patterns (AOB) with ? wildcards to find structures or code whose address moves but bytes don't. Returns a scan_id.
Instructions
Scan for a byte pattern (an AOB scan) with ? wildcards.
The IDA / Cheat Engine technique for finding a structure or a piece of
code whose address moves between builds but whose surrounding bytes do
not: "48 8B ? ? 00 00 89". Returns a scan_id like
scan_value.
:param pattern: space-separated hex bytes, where ? or ?? is a
single-byte wildcard.
Note that this covers the target's readable, non-shared regions —
heap, stack and anonymous mappings. File-backed code (a .dll /
.so / .dylib image) is a shared mapping and is deliberately
excluded, so patterns matching instructions inside a loaded module will
not be found here. Reach module code through process_info's module
bases plus a static offset instead.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| pattern | Yes | ||
| session_id | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |