![]() |
HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|

Hollows Hunter is a command-line application based on PE-sieve passive memory scanner. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches). While in case of PE-sieve you can select the process only by its PID, Hollows Hunter allows to select them by various criteria, such as:
If no specific target is selected, it proceeds to scan all available processes.
Hollows Hunter allows also for continuous memory scanning, via /loop argument, or by being run as an ETW listener: in /etw mode (64-bit version only).
/help.📦 Uses: PE-sieve (the library version).
❓ PE-sieve FAQ - Frequently Asked Questions
Use recursive clone to get the repo together with all the submodules:
Download the latest release, or read more.
Available also via Chocolatey