![]() |
HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
#include <hh_scanner.h>
Public Member Functions | |
| HHScanner (t_hh_params &_args, time_t _initTime=0) | |
| HHScanReport * | scan () |
| bool | writeToLog (HHScanReport *hh_report) |
| void | summarizeScan (HHScanReport *hh_report, const pesieve::t_results_filter rfilter) |
Static Public Member Functions | |
| static bool | isScannerCompatibile () |
| static t_single_scan_status | shouldScanProcess (const hh_params &hh_args, const time_t hh_initTime, const DWORD pid, const WCHAR *exe_file) |
Protected Member Functions | |
| void | printScanRoundStats (size_t found, size_t ignored_count, size_t not_matched_count) |
| size_t | scanProcesses (HHScanReport &my_report) |
| void | printSingleReport (pesieve::t_report &report) |
| t_single_scan_status | scanNextProcess (DWORD pid, WCHAR *image_buf, HHScanReport &report) |
| void | initOutDir (time_t scan_time, pesieve::t_params &pesieve_args) |
Protected Attributes | |
| t_hh_params & | hh_args |
| std::string | outDir |
| time_t | initTime |
| bool | isScannerWow64 |
Definition at line 24 of file hh_scanner.h.
| HHScanner::HHScanner | ( | t_hh_params & | _args, |
| time_t | _initTime = 0 ) |
|
protected |
|
static |
|
protected |
|
protected |
| HHScanReport * HHScanner::scan | ( | ) |
|
protected |
|
protected |
|
static |
| void HHScanner::summarizeScan | ( | HHScanReport * | hh_report, |
| const pesieve::t_results_filter | rfilter ) |
| bool HHScanner::writeToLog | ( | HHScanReport * | hh_report | ) |
|
protected |
Definition at line 44 of file hh_scanner.h.
|
protected |
Definition at line 48 of file hh_scanner.h.
|
protected |
Definition at line 49 of file hh_scanner.h.
|
protected |
Definition at line 45 of file hh_scanner.h.