Mono - Lua
Jump to navigation
Jump to search
The advanced Mono features of Cheat Engine are controlled by the monoscript.lua script in the autorun directory.
When Cheat Engine attaches to a process, the script checks for mono.dll. If Mono is detected, the matching MonoDataDissector DLL from the autorun directory is injected into the target process. The injected DLL creates a named pipe, and the Lua side communicates with it to perform Mono-related operations.
Contents
Main Methods
| Function | Return Type | Description |
|---|---|---|
| LaunchMonoDataCollector() | Integer | Injects the Mono data collector DLL. Returns 0 on failure, or the monoBase returned by the CMD_INITMONO pipe command. |
| monoTypeToVarType(monoType) | ValueType | Returns the Cheat Engine value type for the given Mono type, such as vtString, vtByte, vtWord, vtDword, vtSingle, vtDouble, or vtPointer. |
| mono_object_getClass(address) | Integer, String | Returns the class ID and class name of the object at the given address. |
| mono_enumDomains() | Table | Returns a table array containing the domain address of each Mono domain. |
| mono_setCurrentDomain(domainId) | Integer | Sets the Mono domain used by the MonoDataCollector. |
| mono_enumAssemblies() | Table | Returns a table containing the assembly IDs for each assembly in the current domain. |
| mono_getImageFromAssembly(assemblyId) | Integer | Returns the image ID for the given assembly. |
| mono_image_get_name(imageId) | String | Returns the name of the assembly image. |
| mono_image_enumClasses(imageId) | Table | Returns a table containing the class IDs for classes in the given assembly image. |
| mono_class_getName(classId) | String | Returns the class name of the given class. |
| mono_class_getNamespace(classId) | String | Returns the namespace of the given class. |
| mono_class_getParent(classId) | Integer | Returns the class ID of the parent class. |
| mono_class_getStaticFieldAddress(domainId, classId) | Integer | Returns the base address for the static field storage area of the given class in the given domain. |
| mono_class_enumFields(classId) | Table | Returns a table containing field objects for the given class. |
| mono_class_enumMethods(classId) | Table | Returns a table containing method objects for the given class. |
| mono_getJitInfo(address) | Table | Returns JIT information for the code address. |
| mono_image_findClass(imageId, namespace, className) | Integer | Returns the class ID for the given namespace and class name in the specified image. |
| mono_findClass(namespace, className) | Integer | Returns the class ID for the given namespace and class name. |
| mono_class_findMethod(classId, methodName) | Integer | Returns the method ID of the given method in the given class. |
| mono_findMethod(namespace, className, methodName) | Integer | Returns the method ID for the given namespace, class name, and method name. |
| mono_method_getName(methodId) | String | Returns the name of the given method. |
| mono_method_getHeader(methodId) | Integer | Returns the method header ID. |
| mono_method_getSignature(methodId) | String, Table, String | Returns the signature result, parameter names, and return type of the method. |
| mono_method_disassemble(methodId) | String | Returns the disassembled IL code for the given method. |
| mono_method_getClass(methodId) | Integer | Returns the class ID that owns the given method. |
| mono_compile_method(methodId) | Integer | JIT-compiles the method if needed and returns the native method address. |
| mono_free_method(methodId) | void | Frees a dynamic method. This only works on dynamic methods and only if the profiler is not being used. |
| mono_methodheader_getILCode(methodHeader) | Integer, Integer | Returns the IL code address and size for the given method header. |
| mono_getILCodeFromMethod(methodId) | Integer, Integer | Gets the method header and returns the IL code address and size. |
| mono_image_rva_map(imageId, offset) | Integer | Maps an image RVA/offset. Exact usage depends on the Mono image context. |
| mono_loadAssemblyFromFile(fname) | Integer | Loads a C# assembly in the target process. |
| mono_invoke_method(domainId, methodId, address, args) | Variant | Invokes a Mono method with the given domain, method, instance address, and arguments. |
Field Object
mono_class_enumFields(classId) returns a table of field objects.
| Field | Type | Description |
|---|---|---|
| field | Integer | The field ID. |
| type | ValueType | The Cheat Engine value type. |
| monotype | Integer | The Mono type. |
| parent | Integer | The parent class ID. |
| offset | Integer | The offset in bytes from the object or static field base address. |
| flags | Integer | The field flags. |
| isStatic | Boolean | True if the field is static. If true, use mono_class_getStaticFieldAddress to get the static field base address. |
| name | String | The field name. |
| typename | String | The type name, usually including namespace, such as System.Int32. |
Method Object
mono_class_enumMethods(classId) returns a table of method objects.
| Field | Type | Description |
|---|---|---|
| method | Integer | The method ID. |
| name | String | The method name. |
JIT Info Object
mono_getJitInfo(address) returns a table with information about the compiled native method at the given address.
| Field | Type | Description |
|---|---|---|
| method | Integer | The method ID. |
| code_start | Integer | The native code start address. |
| code_size | Integer | The native code size in bytes. |
Method Signature Result
mono_method_getSignature(methodId) returns multiple values.
| Return Value | Type | Description |
|---|---|---|
| result | String | The formatted method signature result. |
| parameterNames | Table | A table containing parameter names. |
| returnType | String | The return type string. |
Cheat Engine Hooks
| Function | Return Type | Description |
|---|---|---|
| mono_initialize() | void | Sets up Mono-related hooks, calls the previous open-process hook if present, and schedules mono_OpenProcessMT. |
| mono_OpenProcessMT(t) | void | Called when a process is opened. If t is not nil, it destroys t, enumerates modules looking for mono.dll, and adds Mono menu items to the main form. |
| mono_OpenProcess(processid) | void | Open-process hook used by the Mono integration. |
| mono_structureDissectOverrideCallback(structure, baseaddress) | Boolean/nil | Called by Cheat Engine when a structure is dissected. Returns true if structure members were defined, otherwise nil. |
| mono_structureNameLookupCallback(address) | String, Integer/nil | Called by Cheat Engine when creating a new structure in the structure dissector. Returns classname and current address, or nil. |
| mono_symbolLookupCallback(symbol) | Integer/nil | Called by Cheat Engine when resolving a Mono symbol. Returns an address or nil. |
| mono_addressLookupCallback(address) | String | Called by Cheat Engine's disassembly view to display a Mono symbol name for the given address. |
Mono Dissector Methods
| Function | Description |
|---|---|
| monoform_killform(sender) | Closes or destroys the Mono dissector form. |
| monoform_miShowILDisassemblyClick(sender) | Handles the Show IL Disassembly menu item. |
| monoform_miRejitClick(sender) | Handles the ReJIT menu item. |
| monoform_miGetILCodeClick(sender) | Handles the Get IL Code menu item. |
| monoform_EnumImages(node) | Enumerates images for the selected tree node. |
| monoform_EnumClasses(node) | Enumerates classes for the selected tree node. |
| monoform_EnumFields(node) | Enumerates fields for the selected tree node. |
| monoform_EnumMethods(node) | Enumerates methods for the selected tree node. |
| mono_TVExpanding(sender, node) | Handles Mono tree-view expansion. |
| mono_TVCollapsing(sender, node) | Handles Mono tree-view collapsing. |
| monoform_FindDialogFind(sender) | Handles Mono dissector find dialog searches. |
| monoform_miFindClick(sender) | Handles the Find menu item. |
| monoform_miExpandAllClick(sender) | Handles the Expand All menu item. |
| monoform_miSaveClick(sender) | Handles the Save menu item. |
| mono_dissect() | Opens or initializes the Mono dissector. |
| miMonoActivateClick(sender) | Handles Mono activation from the Cheat Engine menu. |
| miMonoDissectClick(sender) | Handles opening the Mono dissector from the Cheat Engine menu. |
Examples
Launch the Mono data collector
1 local monoBase = LaunchMonoDataCollector()
2
3 if monoBase == 0 then
4 print("Mono data collector could not be launched")
5 else
6 print(string.format("Mono base: %X", monoBase))
7 end
Enumerate Mono domains
1 local domains = mono_enumDomains()
2
3 for i, domain in ipairs(domains) do
4 print(i .. ": " .. string.format("%X", domain))
5 end
Set the current Mono domain
1 local domains = mono_enumDomains()
2
3 if #domains > 0 then
4 local domain = domains[1]
5 mono_setCurrentDomain(domain)
6 end
Enumerate assemblies
1 local assemblies = mono_enumAssemblies()
2
3 for i, assembly in ipairs(assemblies) do
4 local image = mono_getImageFromAssembly(assembly)
5
6 print(i .. ": " .. tostring(mono_image_get_name(image)))
7 end
Find a class
1 local classId = mono_findClass("PlayerNamespace", "PlayerController")
2
3 if classId ~= nil and classId ~= 0 then
4 print("Class found: " .. tostring(classId))
5 end
Enumerate class fields
1 local classId = mono_findClass("PlayerNamespace", "PlayerController")
2
3 local fields = mono_class_enumFields(classId)
4
5 for i, field in ipairs(fields) do
6 print(field.name .. " : " .. field.typename .. " @ " .. string.format("%X", field.offset))
7 end
Enumerate class methods
1 local classId = mono_findClass("PlayerNamespace", "PlayerController")
2
3 local methods = mono_class_enumMethods(classId)
4
5 for i, method in ipairs(methods) do
6 print(method.name .. " = " .. tostring(method.method))
7 end
Find and compile a method
1 local methodId = mono_findMethod("PlayerNamespace", "PlayerController", "TakeDamage")
2
3 if methodId ~= nil and methodId ~= 0 then
4 local address = mono_compile_method(methodId)
5
6 print(string.format("Native address: %X", address))
7 end
Get method signature
1 local methodId = mono_findMethod("PlayerNamespace", "PlayerController", "TakeDamage")
2
3 if methodId ~= nil and methodId ~= 0 then
4 local signature, parameterNames, returnType = mono_method_getSignature(methodId)
5
6 print(signature)
7 print("Returns: " .. tostring(returnType))
8 end
Get JIT information from an address
1 local address = getAddress("GameAssembly.dll+123456")
2 local info = mono_getJitInfo(address)
3
4 if info ~= nil then
5 print("Method: " .. tostring(info.method))
6 print("Code start: " .. string.format("%X", info.code_start))
7 print("Code size: " .. tostring(info.code_size))
8 end