HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
hh_params.cpp
Go to the documentation of this file.
1#include "hh_params.h"
2
4{
5 //reset PE-sieve params:
6 memset(&pesieve_args, 0, sizeof(pesieve::t_params));
7
8 //reset output path:
11 pesieve_args.quiet = true;
12 pesieve_args.no_hooks = true;
13 pesieve_args.results_filter = pesieve::SHOW_SUSPICIOUS;
14
15 suspend_suspicious = false;
16 kill_suspicious = false;
17 loop_scanning = false;
18 etw_scan = false;
19 unique_dir = false;
20
21 quiet = false;
22 log = false;
23 json_output = false;
26}
27
29{
30 //copy PE-sieve params:
31 ::memcpy(&pesieve_args, &other.pesieve_args, sizeof(pesieve::t_params));
32
33 // copy HHParams
34 this->out_dir = other.out_dir;
35 this->cache_mode = other.cache_mode;
36
38 this->kill_suspicious = other.kill_suspicious;
39 this->loop_scanning = other.loop_scanning;
40 this->etw_scan = other.etw_scan;
41 this->unique_dir = other.unique_dir;
42
43 this->quiet = other.quiet;
44 this->log = other.log;
45 this->json_output = other.json_output;
46 this->ptimes = other.ptimes;
47
48 // copy lists:
49 this->names_list = other.names_list;
50 this->pids_list = other.pids_list;
52 this->process_arch = other.process_arch;
53 return *this;
54}
#define HH_DEFAULT_DIR
Definition hh_params.h:8
#define TIME_UNDEFINED
Definition hh_params.h:7
@ PROCESS_ALL
Definition hh_params.h:19
@ CACHE_AUTO
autodetect if cache should be enabled
Definition hh_params.h:13
hh_params & operator=(const hh_params &other)
Definition hh_params.cpp:28
void init()
Definition hh_params.cpp:3
std::set< long > pids_list
Definition hh_params.h:41
bool log
Definition hh_params.h:36
bool json_output
Definition hh_params.h:37
bool kill_suspicious
Definition hh_params.h:34
std::set< std::wstring > ignored_names_list
Definition hh_params.h:42
pesieve::t_params pesieve_args
Definition hh_params.h:44
std::string out_dir
Definition hh_params.h:29
bool etw_scan
Definition hh_params.h:32
bool quiet
Definition hh_params.h:35
t_process_type process_arch
Definition hh_params.h:43
std::set< std::wstring > names_list
Definition hh_params.h:40
t_cache_mode cache_mode
Definition hh_params.h:39
bool loop_scanning
Definition hh_params.h:31
bool suspend_suspicious
Definition hh_params.h:33
bool unique_dir
Definition hh_params.h:30
LONGLONG ptimes
Definition hh_params.h:38