ropshell> use eafc3f67a1602eb1d35dde313578ab63 (download)
name         : ntdll.dll (x86_64/PE)
base address : 0x180001000
total gadgets: 6464
ropshell> suggest
call
    > 0x1800144cf : call rax
    > 0x18003b123 : call rbx
    > 0x18000e55b : call rcx
    > 0x180006459 : call rdx
    > 0x180113a1d : call rsi
jmp
    > 0x180006b0a : push rsp; ret
    > 0x180004d8b : jmp rax
    > 0x180039b67 : jmp rbx
    > 0x180003b77 : jmp rcx
    > 0x1800a47fe : jmp rdx
load mem
    > 0x180074aa0 : movzx eax, [rcx]; ret
    > 0x1800fccad : mov rax, [r10 + 0x38]; ret
    > 0x180071636 : mov eax, [rcx + 0x16b0]; ret
    > 0x1800fccae : mov eax, [rdx + 0x38]; ret
    > 0x1800dca40 : mov ecx, [rax]; add cl, ch; ret 0
load reg
    > 0x1800372cc : pop rax; ret
    > 0x1800011a4 : pop rbx; ret
    > 0x18009227b : pop rcx; ret
    > 0x1800b5752 : pop rdx; ret
    > 0x180006b46 : pop rsi; ret
pop pop ret
    > 0x18008fc38 : pop r11; ret
    > 0x18008fc36 : pop r10; pop r11; ret
    > 0x18000bb40 : pop r12; pop rdi; pop rbp; ret
    > 0x1800017f8 : pop r12; pop rdi; pop rsi; pop rbp; ret
    > 0x18000c4fa : pop r12; pop rdi; pop rsi; pop rbp; pop rbx; ret
sp lifting
    > 0x1800a5758 : add rsp, 0x10; ret
    > 0x1800a5758 : add rsp, 0x10; ret
    > 0x180002e64 : add rsp, 0x28; ret
    > 0x180002a3b : add rsp, 0x38; ret
    > 0x1800598fe : add rsp, 0x438; ret
stack pivoting
    > 0x180017888 : xchg eax, esp; ret
    > 0x18002377a : mov rsp, r11; pop r14; ret
    > 0x18002377b : mov esp, ebx; pop r14; ret
    > 0x18010ff26 : lea rsp, [rbp + 0x10]; pop rbp; ret
    > 0x18010ff27 : lea esp, [rbp + 0x10]; pop rbp; ret
syscall
    > 0x1800a07f2 : syscall ; ret
write mem
    > 0x180032a58 : add [rbx], edi; ret
    > 0x18007186d : add [rdi], ecx; ret
    > 0x18007186c : add [r15], ecx; ret
    > 0x18008634d : add [rax + 0xf], ecx; ret
    > 0x1800766fa : add [rax + 1], edi; ret