ropshell> use 97603dc4df5410ccf9a23a59f14c5b2f (download)
name         : ntdll.dll (x86_64/PE)
base address : 0x180001000
total gadgets: 6342
ropshell> suggest
call
    > 0x18002fbee : call rax
    > 0x180004d11 : call rbx
    > 0x1800908f6 : call rsp
    > 0x18008cf3f : call r8
    > 0x1800908f5 : call r12
jmp
    > 0x18003161b : jmp rax
    > 0x18001b877 : jmp rcx
    > 0x1800a162e : jmp rdx
    > 0x180065e0d : jmp rsi
    > 0x18004ed45 : jmp rsp
load mem
    > 0x18006c740 : movzx eax, [rcx]; ret
    > 0x1800ff67e : mov rax, [r10 + 0x38]; ret
    > 0x180061c36 : mov eax, [rcx + 0x16b0]; ret
    > 0x1800ff67f : mov eax, [rdx + 0x38]; ret
    > 0x180092587 : movzx ecx, [rdx]; sub eax, ecx; ret
load reg
    > 0x180006794 : pop rax; ret
    > 0x18000137d : pop rbx; ret
    > 0x18001a853 : pop rcx; ret
    > 0x18000132d : pop rsi; ret
    > 0x1800010df : pop rdi; ret
pop pop ret
    > 0x18008cc28 : pop r11; ret
    > 0x18008cc26 : pop r10; pop r11; ret
    > 0x180029f11 : pop r12; pop rbp; pop rbx; ret
    > 0x180031072 : pop r12; pop rdi; pop rbp; pop rbx; ret
    > 0x180003997 : pop r12; pop rdi; pop rsi; pop rbp; pop rbx; ret
sp lifting
    > 0x1800a27e8 : add rsp, 0x10; ret
    > 0x1800a27e8 : add rsp, 0x10; ret
    > 0x18006c21f : add rsp, 0x238; ret
    > 0x18000144b : add rsp, 0x38; ret
    > 0x18007da2a : add rsp, 0x438; ret
stack pivoting
    > 0x1800501f6 : xchg eax, esp; ret
    > 0x1800151e3 : mov rsp, r11; pop r14; ret
    > 0x1800151e4 : mov esp, ebx; pop r14; ret
    > 0x180110c92 : lea rsp, [rbp + 0x10]; pop rbp; ret
    > 0x180110c93 : lea esp, [rbp + 0x10]; pop rbp; ret
syscall
    > 0x18009d4f2 : syscall ; ret
write mem
    > 0x18007fd77 : add [rbx], edi; ret
    > 0x18007899d : add [rdi], ecx; ret
    > 0x18007899c : add [r15], ecx; ret
    > 0x18007225a : add [rax + 1], edi; ret
    > 0x18006d436 : add [rbx + 0x27401f8], eax; ret