ropshell> use daf4439caa84c2ca4f6e1b7b20a89f19 (download)
name         : ntdll.dll (x86_64/PE)
base address : 0x180001000
total gadgets: 6609
ropshell> suggest
call
    > 0x1800744e1 : call rax
    > 0x18003c51c : call rbx
    > 0x1801169ad : call rcx
    > 0x180093366 : call rsp
    > 0x18008f793 : call r8
jmp
    > 0x18000d97e : push rsp; ret
    > 0x18008f0bc : jmp rax
    > 0x18001c4dd : jmp rcx
    > 0x1800a442e : jmp rdx
    > 0x180040f78 : jmp [rax]
load mem
    > 0x18006ea00 : movzx eax, [rcx]; ret
    > 0x1800d84aa : mov eax, [rcx + 0x16b0]; ret
    > 0x18010cce5 : mov eax, [rdx + 0x38]; ret
    > 0x1801264a0 : mov eax, [rdi]; add bh, bh; ret
    > 0x1800950f6 : movzx ecx, [rdx]; sub eax, ecx; ret
load reg
    > 0x18000519c : pop rax; ret
    > 0x180001297 : pop rbx; ret
    > 0x180084f4d : pop rcx; ret
    > 0x1800589a6 : pop rdx; ret
    > 0x18000123e : pop rsi; ret
pop pop ret
    > 0x18008f0d8 : pop r11; ret
    > 0x18008f0d6 : pop r10; pop r11; ret
    > 0x18000b4fb : pop r12; pop rdi; pop rbp; ret
    > 0x1800014a9 : pop r12; pop rdi; pop rsi; pop rbp; ret
    > 0x18000e79d : pop r12; pop rdi; pop rsi; pop rbp; pop rbx; ret
sp lifting
    > 0x1800a50f8 : add rsp, 0x10; ret
    > 0x1800a50f8 : add rsp, 0x10; ret
    > 0x1800afffb : add rsp, 0x238; ret
    > 0x1800087e1 : add rsp, 0x38; ret
    > 0x18007fe63 : add rsp, 0x438; ret
stack pivoting
    > 0x1800304e4 : xchg eax, esp; ret
    > 0x180028a29 : mov rsp, r11; pop r14; ret
    > 0x180028a2a : mov esp, ebx; pop r14; ret
    > 0x180124912 : lea rsp, [rbp + 0x10]; pop rbp; ret
    > 0x1800e93bd : xchg esp, ebx; lahf ; xor eax, eax; ret
syscall
    > 0x18009fcc2 : syscall ; ret
write mem
    > 0x18010210f : adc [rax], r10; ret
    > 0x180102110 : adc [rax], edx; ret
    > 0x180050e2f : add [rbx], edi; ret
    > 0x1800a7188 : adc [rdx], eax; ret
    > 0x180077cc8 : add [rdi], ecx; ret