PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
All Classes Namespaces Files Functions Variables Typedefs Enumerations Enumerator Friends Macros Pages
ProcessSymbolsManager Member List

This is the complete list of members for ProcessSymbolsManager, including all inherited members.

dumpSymbolInfo(const ULONG_PTR addr)ProcessSymbolsManagerinline
FreeSymbols()ProcessSymbolsManagerinlineprotected
funcNameFromAddr(IN const ULONG_PTR addr, OUT OPTIONAL size_t *displacement=nullptr)ProcessSymbolsManagerinline
hProcessProcessSymbolsManagerprotected
InitSymbols(HANDLE _hProcess)ProcessSymbolsManagerinline
isInitProcessSymbolsManagerprotected
IsInitialized()ProcessSymbolsManagerinline
normalizeSyscallPrefix(std::string &funcName)ProcessSymbolsManagerinline
ProcessSymbolsManager()ProcessSymbolsManagerinline
~ProcessSymbolsManager()ProcessSymbolsManagerinline