AobscanFast 2.0.0

dotnet add package AobscanFast --version 2.0.0
                    
NuGet\Install-Package AobscanFast -Version 2.0.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="AobscanFast" Version="2.0.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="AobscanFast" Version="2.0.0" />
                    
Directory.Packages.props
<PackageReference Include="AobscanFast" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add AobscanFast --version 2.0.0
                    
#r "nuget: AobscanFast, 2.0.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package AobscanFast@2.0.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=AobscanFast&version=2.0.0
                    
Install as a Cake Addin
#tool nuget:?package=AobscanFast&version=2.0.0
                    
Install as a Cake Tool

<div align="center">

<img src="https://img.icons8.com/dusk/128/memory-slot.png" alt="logo" width="100" height="auto" />

<h1>⚡ AobscanFast</h1>

<p> <b>High-performance memory pattern (AOB) scanner for Windows and Linux.</b> <br> SIMD-accelerated, parallel, cross-platform — written in modern C#. </p>

<a href="#"> <img src="https://img.shields.io/badge/.NET-10.0-512BD4?style=flat-square&logo=dotnet" alt=".NET Version" /> </a> <a href="#"> <img src="https://img.shields.io/badge/Platform-Windows%20|%20Linux-0078D6?style=flat-square&logo=windows" alt="Platform" /> </a> <a href="#"> <img src="https://img.shields.io/badge/SIMD-AVX512%20|%20AVX2%20|%20SSE2-red?style=flat-square" alt="SIMD" /> </a>

</div>


Overview

AobscanFast scans process memory for Array-of-Bytes (AOB) signatures. It is designed for game modding, reverse engineering, debuggers, diagnostics — any tool that needs to locate byte sequences in live process memory.

Key features:

  • Cross-platform — Windows (Win32 API) and Linux (/proc/pid/mem + /proc/pid/maps)
  • SIMD cascade — automatically uses Vector512 (AVX-512), Vector256 (AVX2), or Vector128 (SSE2) depending on CPU capabilities
  • Parallel scanning — memory is split into configurable chunks (default 256 KB) and scanned concurrently via Parallel.ForEach
  • Zero-allocation pathsArrayPool<byte>, Span<T>, stackalloc throughout; no per-chunk allocations in the hot loop
  • Strategy pattern — parsers and matchers are selected automatically based on the pattern syntax
  • DI-ready — all dependencies injected through interfaces; AobScannerFactory for quick start
  • Configurable — chunk size, parallelism degree, and result limit (AobScanOptions.ChunkSize, MaxDegreeOfParallelism, MaxResults)

Installation

Install from NuGet:

dotnet add package AobscanFast

Install the Python binding from PyPI:

pip install aobscanfast
from aobscanfast import AobScanner

with AobScanner(pid=1234) as scanner:
    matches = scanner.scan("48 8B ?? ?? ?? AA")

Or for local development, clone and add a project reference:

git clone https://github.com/larkliy/AobscanFast.git
dotnet add reference AobscanFast/AobscanFast.csproj

Usage

1. Scan a remote process

using AobscanFast.Infrastructure.Windows;
using AobscanFast.Services;

var handler = new WinProcessHandler();
uint? pid = handler.FindIdByName("notepad");

using var handle = handler.OpenProcess(pid.Value);

var scanner = AobScannerFactory.ForRemoteProcess(handle);
var results = scanner.Scan("48 8B ?? ?? ?? AA");
var first   = scanner.ScanFirst("48 8B ?? ?? ?? AA");

2. Module-scoped scan

Limit the range to a specific module for better performance.

var module = handler.GetModuleInfo(pid.Value, "GameAssembly.dll");

if (module != null)
{
    var options = new AobScanOptions
    {
        MinScanAddress = module.Value.BaseAddress,
        MaxScanAddress = module.Value.BaseAddress + (nint)module.Value.Size
    };

    var results = scanner.Scan("F3 0F 10 ?? ?? ??", options);
}

3. In-process scan (injected DLL / NativeAOT)

using AobscanFast.Services;

var scanner = AobScannerFactory.ForCurrentProcess();
var results = scanner.Scan("48 8B ?? ?? ?? AA");

4. Custom scan options

var options = new AobScanOptions
{
    MinScanAddress = 0x7f0000000000,
    MaxScanAddress = 0x7fffffffffff,
    ChunkSize = 1024 * 1024,       // default 256 KB
    MaxDegreeOfParallelism = 4,    // default -1 (all cores)
    MaxResults = 10               // stop after finding 10 matches
};

var firstTen = scanner.Scan("48 8B ?? ?? ?? AA", options);

5. Linux

using AobscanFast.Infrastructure.Linux;
using AobscanFast.Services;

var handler = new LinuxProcessHandler();
uint? pid = handler.FindIdByName("bash");

using var handle = handler.OpenProcess(pid.Value);

var scanner = AobScannerFactory.ForRemoteProcess(handle);
var results = scanner.Scan("48 8B ?? ?? ?? AA");

Pattern syntax

Type Example Description
Solid (exact) AA BB CC DD No wildcards — uses Span<byte>.IndexOf
Byte mask AA ?? CC ?? ?? matches any byte — SIMD masked comparison
Nibble mask ?A B? ? masks a single nibble — per-nibble mask

Patterns must be space-separated (tabs or other whitespace will cause a parse error).


Architecture

                    AobScanner (orchestrator)
                         |
          +--------------+--------------+
          |              |              |
   IProcessHandler  IRegionEnumerator  IMemoryAccessor
   (Win/Linux)      (Win/Linux)        (Win/Linux)
          |
   IMemoryRangePlanner → RegionProcessor (merge + chunk)
          |
   IPatternParserResolver → SolidParser / MaskParser / HalfMaskParser
          |
   IPatternMatcherResolver → SolidMatcher / MaskMatcher (SIMD)

Patterns are parsed once into an AobPattern (bytes, mask, search sequence). The longest contiguous unmasked sequence is extracted at parse time and used as a fast pre-filter during matching, drastically reducing the number of SIMD comparisons.


Performance

  • Search-sequence pre-filter — only positions where the longest solid run matches are verified with SIMD
  • Configurable chunk size (default 256 KB) with overlap (patternLength - 1) — balances parallelism with cache efficiency
  • Region merging — adjacent memory regions are merged before chunking to minimize system calls
  • SIMD cascadeMaskMatcher.IsMatch() tries AVX-512 → AVX2 → SSE2 → scalar fallback
  • Safe current-process readsReadProcessMemory snapshots protected by a VirtualQuery probe
  • Max results — optional result limit cancels remaining work via linked CancellationTokenSource

Project structure

AobscanFast/
  Core/
    Interfaces/      — all contracts
    Models/          — MemoryRange, AobScanOptions, AobPattern
    Parsing/         — SolidParser, MaskParser, HalfMaskParser
    Matching/        — SolidMatcher, MaskMatcher (SIMD)
    Helpers/         — RegionProcessor, ParserHelpers
  Services/          — AobScanner, AobScannerFactory
  Infrastructure/
    Windows/         — Win32 API implementations
    Linux/           — /proc-based implementations
AobscanFast.Sample/  — demo console app
AobscanFast.Tests/   — xUnit tests

Building and testing

dotnet build
dotnet test AobscanFast.Tests/AobscanFast.Tests.csproj
dotnet run --project AobscanFast.Sample

Contributing

Contributions are welcome — Linux port, new SIMD routines, additional pattern formats.

  1. Fork the repo
  2. Create your branch: git checkout -b feature/my-feature
  3. Commit your changes
  4. Push and open a Pull Request

<div align="center"> <i>Engineered for speed, architected for humans.</i> </div>

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2.0.0 53 8/15/2026
1.0.3 56 8/15/2026
1.0.2 55 8/15/2026
1.0.1 89 8/8/2026
1.0.0 84 8/8/2026