PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
#include <params.h>
Public Member Functions | |
PEsieveParams (const std::string &version) | |
bool | fillStringParam (const std::string ¶mId, PARAM_STRING &strparam) |
void | fillStruct (t_params &ps) |
void | printBanner () |
|
inline |
|
inline |
|
inline |
|
inline |