![]() |
HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
#include <pe_sieve_api.h>#include <string>#include <set>Go to the source code of this file.
Classes | |
| struct | hh_params |
Macros | |
| #define | TIME_UNDEFINED LONGLONG(-1) |
| #define | HH_DEFAULT_DIR "hollows_hunter.dumps" |
Typedefs | |
| typedef struct hh_params | t_hh_params |
Enumerations | |
| enum | t_cache_mode { CACHE_DISABLED = 0 , CACHE_AUTO , CACHE_ENABLED , CACHE_MODES_COUNT } |
| enum | t_process_type { PROCESS_ALL = 0 , PROCESS_32BIT = 1 , PROCESS_64BIT = 2 , PROCESS_TYPES_COUNT } |
| #define HH_DEFAULT_DIR "hollows_hunter.dumps" |
Definition at line 8 of file hh_params.h.
| #define TIME_UNDEFINED LONGLONG(-1) |
Definition at line 7 of file hh_params.h.
| typedef struct hh_params t_hh_params |
| enum t_cache_mode |
| Enumerator | |
|---|---|
| CACHE_DISABLED | cache always disabled |
| CACHE_AUTO | autodetect if cache should be enabled |
| CACHE_ENABLED | cache always enabled |
| CACHE_MODES_COUNT | |
Definition at line 11 of file hh_params.h.
| enum t_process_type |
| Enumerator | |
|---|---|
| PROCESS_ALL | |
| PROCESS_32BIT | |
| PROCESS_64BIT | |
| PROCESS_TYPES_COUNT | |
Definition at line 18 of file hh_params.h.