125 std::stringstream ss1;
126 ss1 <<
"Scan only processes with given PIDs.";
127 std::stringstream ss2;
128 ss2 << INFO_SPACER <<
"Example: 5367" << PARAM_LIST_SEPARATOR <<
"0xa90";
129 this->addParam(
new IntListParam(
PARAM_PID,
false, PARAM_LIST_SEPARATOR));
130 this->setInfo(
PARAM_PID, ss1.str(), ss2.str());
133 std::stringstream ss1;
134 ss1 <<
"Scan only processes with given names.";
135 std::stringstream ss2;
136 ss2 << INFO_SPACER <<
"Example: iexplore.exe" << PARAM_LIST_SEPARATOR <<
"firefox.exe";
137 this->addParam(
new StringListParam(
PARAM_PNAME,
false, PARAM_LIST_SEPARATOR));
141 std::stringstream ss1;
142 ss1 <<
"Make a unique, timestamped directory for the output of each scan.";
143 std::stringstream ss2;
144 ss2 << INFO_SPACER <<
"Prevents overwriting results from previous scans.";
149 std::stringstream ss1;
150 ss1 <<
"Do not scan process/es with given name/s.";
151 std::stringstream ss2;
152 ss2 << INFO_SPACER <<
"Example: explorer.exe" << PARAM_LIST_SEPARATOR <<
"conhost.exe";
157 this->addParam(
new IntParam(
PARAM_PTIMES,
false, IntParam::INT_BASE_DEC));
158 this->setInfo(
PARAM_PTIMES,
"Skip processes created N or more seconds before the scanner start.");
163 EnumParam* enumParam =
new EnumParam(
PARAM_ARCH,
"process_arch",
false);
165 this->addParam(enumParam);
166 this->setInfo(
PARAM_ARCH,
"Scan only processes with given architecture.");
173 this->setInfo(
PARAM_SUSPEND,
"Suspend processes detected as suspicious.");
175 this->addParam(
new BoolParam(
PARAM_LOG,
false));
176 this->setInfo(
PARAM_LOG,
"Append each scan summary to the log.");
178 this->addParam(
new BoolParam(
PARAM_KILL,
false));
179 this->setInfo(
PARAM_KILL,
"Kill processes detected as suspicious.");
182 this->setInfo(
PARAM_HOOKS,
"Detect inline hooks and in-memory patches.");
184 this->addParam(
new BoolParam(
PARAM_LOOP,
false));
185 this->setInfo(
PARAM_LOOP,
"Enable continuous scanning.");
186 BoolParam* etwParam =
new BoolParam(
PARAM_ETW,
false);
188 this->addParam(etwParam);
189 this->setInfo(
PARAM_ETW,
"Use ETW (requires Administrator privilege).");
191 etwParam->setActive(
false);
192 this->setInfo(
PARAM_ETW,
"Use ETW (disabled).");
195 enumParam =
new EnumParam(
PARAM_IMP_REC,
"imprec_mode",
false);
197 this->addParam(enumParam);
198 this->setInfo(
PARAM_IMP_REC,
"Set in which mode the ImportTable should be recovered");
199 for (
size_t i = 0; i < PE_IMPREC_MODES_COUNT; i++) {
200 t_imprec_mode mode = (t_imprec_mode)(i);
207 this->addParam(enumParam);
209 for (
size_t i = 0; i < OUT_FILTERS_COUNT; i++) {
210 t_output_filter mode = (t_output_filter)(i);
217 this->addParam(enumParam);
219 for (DWORD i = SHOW_SUSPICIOUS; i <= SHOW_ALL; i++) {
220 t_results_filter mode = (t_results_filter)(i);
222 if (info.empty())
continue;
229 std::stringstream ss1;
230 ss1 <<
"Do not scan module/s with given name/s.";
231 std::stringstream ss2;
232 ss2 <<
"\t Example: kernel32.dll" << PARAM_LIST_SEPARATOR <<
"user32.dll";
237 this->setInfo(
PARAM_QUIET,
"Print only the summary. Do not log on stdout during the scan.");
239 this->addParam(
new BoolParam(
PARAM_JSON,
false));
240 this->setInfo(
PARAM_JSON,
"Print the JSON report as the summary.");
245 this->addParam(enumParam);
246 this->setInfo(
PARAM_JSON_LVL,
"Level of details of the JSON report.");
247 for (
size_t i = 0; i < JSON_LVL_COUNT; i++) {
248 t_json_level mode = (t_json_level)(i);
254 this->setInfo(
PARAM_MINIDUMP,
"Create a minidump of the full suspicious process.");
258 this->setInfo(
PARAM_REBASE,
"Rebase the module to its original base (if known).");
263 this->addParam(enumParam);
264 this->setInfo(
PARAM_SHELLCODE,
"Detect shellcode implants (by patterns or statistics). ");
265 for (
size_t i = 0; i < SHELLC_COUNT; i++) {
266 t_shellc_mode mode = (t_shellc_mode)(i);
274 this->addParam(enumParam);
275 this->setInfo(
PARAM_OBFUSCATED,
"Detect encrypted content, and possible obfuscated shellcodes.");
276 for (
size_t i = 0; i < OBFUSC_COUNT; i++) {
277 t_obfusc_mode mode = (t_obfusc_mode)(i);
284 this->setInfo(
PARAM_THREADS,
"Scan threads' callstack. Detect shellcodes, incl. 'sleeping beacons'.");
288 this->setInfo(
PARAM_REFLECTION,
"Make a process reflection before scan.",
"\t This allows i.e. to force-read inaccessible pages.");
291 enumParam =
new EnumParam(
PARAM_CACHE,
"cache_mode",
false);
293 this->addParam(enumParam);
294 this->setInfo(
PARAM_CACHE,
"Use modules caching. This can speed up the scan (on the cost of memory consumption).\n");
302 enumParam =
new EnumParam(
PARAM_IAT,
"iat_scan_mode",
false);
304 this->addParam(enumParam);
305 this->setInfo(
PARAM_IAT,
"Scan for IAT hooks.");
306 for (
size_t i = 0; i < PE_IATS_MODES_COUNT; i++) {
307 t_iat_scan_mode mode = (t_iat_scan_mode)(i);
313 this->setInfo(
PARAM_SYMBOLS,
"Autodownload symbols for scanned modules.");
316 this->setInfo(
PARAM_PATTERN,
"Set additional shellcode patterns (file in the SIG format).");
321 this->addParam(enumParam);
322 this->setInfo(
PARAM_DOTNET_POLICY,
"Set the policy for scanning managed processes (.NET).");
323 for (
size_t i = 0; i < PE_DNET_COUNT; i++) {
324 t_dotnet_policy mode = (t_dotnet_policy)(i);
330 enumParam =
new EnumParam(
PARAM_DATA,
"data_scan_mode",
false);
332 this->addParam(enumParam);
333 this->setInfo(
PARAM_DATA,
"Set if non-executable pages should be scanned.");
334 for (
size_t i = 0; i < PE_DATA_COUNT; i++) {
335 t_data_scan_mode mode = (t_data_scan_mode)(i);
343 this->addParam(enumParam);
344 this->setInfo(
PARAM_DUMP_MODE,
"Set in which mode the detected PE files should be dumped.");
345 for (
size_t i = 0; i < PE_DUMP_MODES_COUNT; i++) {
346 t_dump_mode mode = (t_dump_mode)(i);
351 this->addParam(
new StringParam(
PARAM_DIR,
false));
352 this->setInfo(
PARAM_DIR,
"Set a root directory for the output (default: \""+ std::string(
HH_DEFAULT_DIR) +
"\").");
355 std::string str_group =
"7. output options";
356 this->addGroup(
new ParamGroup(str_group));
357 this->addParamToGroup(
PARAM_DIR, str_group);
362 this->addParamToGroup(
PARAM_LOG, str_group);
365 str_group =
"2. scanner settings";
366 this->addGroup(
new ParamGroup(str_group));
373 str_group =
"4. scan options";
374 this->addGroup(
new ParamGroup(str_group));
376 this->addParamToGroup(
PARAM_IAT, str_group);
382 this->addParamToGroup(
PARAM_ETW, str_group);
384 str_group =
"5. dump options";
385 this->addGroup(
new ParamGroup(str_group));
391 str_group =
"3. scan exclusions";
392 this->addGroup(
new ParamGroup(str_group));
397 str_group =
"1. scan targets";
398 this->addGroup(
new ParamGroup(str_group));
399 this->addParamToGroup(
PARAM_PID, str_group);
404 str_group =
"6. post-scan actions";
405 this->addGroup(
new ParamGroup(str_group));
464 StringListParam* myParam =
dynamic_cast<StringListParam*
>(this->getParam(
PARAM_PNAME));
465 if (myParam && myParam->isSet()) {
466 std::set<std::string> names_list;
467 myParam->stripToElements(names_list);
468 for (
auto itr = names_list.begin(); itr != names_list.end(); itr++) {
474 if (myParam && myParam->isSet()) {
475 std::set<std::string> ignored_names_list;
476 myParam->stripToElements(ignored_names_list);
477 for (
auto itr = ignored_names_list.begin(); itr != ignored_names_list.end(); itr++) {
481 IntListParam* myIntParam =
dynamic_cast<IntListParam*
>(this->getParam(
PARAM_PID));
482 if (myIntParam && myIntParam->isSet()) {
483 myIntParam->stripToIntElements(ps.
pids_list);