HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
Go to the source code of this file.
Functions | |
std::string | translate_dump_mode (const DWORD dump_mode) |
std::string | translate_out_filter (const pesieve::t_output_filter o_filter) |
std::string | translate_results_filter (const pesieve::t_results_filter r_filter) |
std::string | results_filter_to_id (const DWORD r_filter) |
std::string | translate_imprec_mode (const pesieve::t_imprec_mode imprec_mode) |
std::string | translate_iat_scan_mode (const pesieve::t_iat_scan_mode mode) |
std::string | translate_dotnet_policy (const pesieve::t_dotnet_policy &mode) |
std::string | translate_json_level (const pesieve::t_json_level &mode) |
std::string | shellc_mode_mode_to_id (const pesieve::t_shellc_mode &mode) |
std::string | translate_shellc_mode (const pesieve::t_shellc_mode &mode) |
std::string | translate_obfusc_mode (const pesieve::t_obfusc_mode &mode) |
std::string | obfusc_mode_mode_to_id (const pesieve::t_obfusc_mode &mode) |
std::string | translate_data_mode (const pesieve::t_data_scan_mode &mode) |
std::string | dump_mode_to_id (const DWORD dump_mode) |
std::string | imprec_mode_to_id (const pesieve::t_imprec_mode imprec_mode) |
std::string dump_mode_to_id | ( | const DWORD | dump_mode | ) |
Definition at line 202 of file pe_sieve_params_info.cpp.
std::string imprec_mode_to_id | ( | const pesieve::t_imprec_mode | imprec_mode | ) |
Definition at line 217 of file pe_sieve_params_info.cpp.
std::string obfusc_mode_mode_to_id | ( | const pesieve::t_obfusc_mode & | mode | ) |
Definition at line 170 of file pe_sieve_params_info.cpp.
std::string results_filter_to_id | ( | const DWORD | r_filter | ) |
Definition at line 46 of file pe_sieve_params_info.cpp.
std::string shellc_mode_mode_to_id | ( | const pesieve::t_shellc_mode & | mode | ) |
Definition at line 123 of file pe_sieve_params_info.cpp.
std::string translate_data_mode | ( | const pesieve::t_data_scan_mode & | mode | ) |
Definition at line 183 of file pe_sieve_params_info.cpp.
std::string translate_dotnet_policy | ( | const pesieve::t_dotnet_policy & | mode | ) |
Definition at line 93 of file pe_sieve_params_info.cpp.
std::string translate_dump_mode | ( | const DWORD | dump_mode | ) |
Definition at line 5 of file pe_sieve_params_info.cpp.
std::string translate_iat_scan_mode | ( | const pesieve::t_iat_scan_mode | mode | ) |
Definition at line 78 of file pe_sieve_params_info.cpp.
std::string translate_imprec_mode | ( | const pesieve::t_imprec_mode | imprec_mode | ) |
Definition at line 59 of file pe_sieve_params_info.cpp.
std::string translate_json_level | ( | const pesieve::t_json_level & | mode | ) |
Definition at line 110 of file pe_sieve_params_info.cpp.
std::string translate_obfusc_mode | ( | const pesieve::t_obfusc_mode & | mode | ) |
Definition at line 155 of file pe_sieve_params_info.cpp.
std::string translate_out_filter | ( | const pesieve::t_output_filter | o_filter | ) |
Definition at line 20 of file pe_sieve_params_info.cpp.
std::string translate_results_filter | ( | const pesieve::t_results_filter | r_filter | ) |
Definition at line 33 of file pe_sieve_params_info.cpp.
std::string translate_shellc_mode | ( | const pesieve::t_shellc_mode & | mode | ) |
Definition at line 138 of file pe_sieve_params_info.cpp.