HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for ETWProfile, including all inherited members.
allocation | ETWProfile | |
DELIM | ETWProfile | protectedstatic |
ETWProfile(bool _process_start=false, bool _img_load=false, bool _allocation=false, bool _tcpip=false, bool _obj_mgr=false) | ETWProfile | inline |
fillSettings(std::string line) | ETWProfile | protected |
img_load | ETWProfile | |
initProfile(const std::string &fileName) | ETWProfile | inline |
isEnabled() | ETWProfile | inline |
loadIni(const std::string &fileName) | ETWProfile | |
obj_mgr | ETWProfile | |
process_start | ETWProfile | |
saveIni(const std::string &fileName) | ETWProfile | |
setAll() | ETWProfile | inline |
stripComments(std::string &str) | ETWProfile | protected |
tcpip | ETWProfile |