HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
hh_params.h
Go to the documentation of this file.
1#pragma once
2
3#include <pe_sieve_api.h>
4#include <string>
5#include <set>
6
7#define TIME_UNDEFINED LONGLONG(-1)
8#define HH_DEFAULT_DIR "hollows_hunter.dumps"
9
10
17
24
25//HollowsHunter's parameters:
26typedef struct hh_params
27{
28public:
29 std::string out_dir;
35 bool quiet;
36 bool log;
38 LONGLONG ptimes;
40 std::set<std::wstring> names_list;
41 std::set<long> pids_list;
42 std::set<std::wstring> ignored_names_list;
44 pesieve::t_params pesieve_args; //PE-sieve parameters
45
46 void init();
47 hh_params& operator=(const hh_params& other);
48
50
struct hh_params t_hh_params
t_process_type
Definition hh_params.h:18
@ PROCESS_64BIT
Definition hh_params.h:21
@ PROCESS_32BIT
Definition hh_params.h:20
@ PROCESS_TYPES_COUNT
Definition hh_params.h:22
@ PROCESS_ALL
Definition hh_params.h:19
t_cache_mode
Definition hh_params.h:11
@ CACHE_AUTO
autodetect if cache should be enabled
Definition hh_params.h:13
@ CACHE_ENABLED
cache always enabled
Definition hh_params.h:14
@ CACHE_DISABLED
cache always disabled
Definition hh_params.h:12
@ CACHE_MODES_COUNT
Definition hh_params.h:15
hh_params & operator=(const hh_params &other)
Definition hh_params.cpp:28
void init()
Definition hh_params.cpp:3
std::set< long > pids_list
Definition hh_params.h:41
bool log
Definition hh_params.h:36
bool json_output
Definition hh_params.h:37
bool kill_suspicious
Definition hh_params.h:34
std::set< std::wstring > ignored_names_list
Definition hh_params.h:42
pesieve::t_params pesieve_args
Definition hh_params.h:44
std::string out_dir
Definition hh_params.h:29
bool etw_scan
Definition hh_params.h:32
bool quiet
Definition hh_params.h:35
t_process_type process_arch
Definition hh_params.h:43
std::set< std::wstring > names_list
Definition hh_params.h:40
t_cache_mode cache_mode
Definition hh_params.h:39
bool loop_scanning
Definition hh_params.h:31
bool suspend_suspicious
Definition hh_params.h:33
bool unique_dir
Definition hh_params.h:30
LONGLONG ptimes
Definition hh_params.h:38