![]() |
HollowsHunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
#include <etw_settings.h>
Public Member Functions | |
| ETWProfile (bool _process_start=false, bool _img_load=false, bool _allocation=false, bool _tcpip=false, bool _obj_mgr=false) | |
| bool | initProfile (const std::string &fileName) |
| bool | loadIni (const std::string &fileName) |
| bool | saveIni (const std::string &fileName) |
| void | setAll () |
| bool | isEnabled () |
Public Attributes | |
| bool | process_start |
| bool | img_load |
| bool | allocation |
| bool | tcpip |
| bool | obj_mgr |
Protected Member Functions | |
| bool | fillSettings (const std::string &line) |
| void | stripComments (std::string &str) |
Static Protected Attributes | |
| static const char | DELIM = '=' |
Definition at line 5 of file etw_settings.h.
|
inline |
Definition at line 13 of file etw_settings.h.
|
protected |
|
inline |
|
inline |
Definition at line 40 of file etw_settings.h.
| bool ETWProfile::loadIni | ( | const std::string & | fileName | ) |
| bool ETWProfile::saveIni | ( | const std::string & | fileName | ) |
|
inline |
Definition at line 31 of file etw_settings.h.
|
protected |
Definition at line 98 of file etw_settings.cpp.
| bool ETWProfile::allocation |
Definition at line 9 of file etw_settings.h.
|
staticprotected |
Definition at line 55 of file etw_settings.h.
| bool ETWProfile::img_load |
Definition at line 8 of file etw_settings.h.
| bool ETWProfile::obj_mgr |
Definition at line 11 of file etw_settings.h.
| bool ETWProfile::process_start |
Definition at line 7 of file etw_settings.h.
| bool ETWProfile::tcpip |
Definition at line 10 of file etw_settings.h.