PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
ProcessSymbolsManager Class Reference

#include <process_symbols.h>

Public Member Functions

 ProcessSymbolsManager ()
 
 ~ProcessSymbolsManager ()
 
bool InitSymbols (HANDLE _hProcess)
 
bool IsInitialized ()
 
std::string funcNameFromAddr (const ULONG_PTR addr)
 
bool dumpSymbolInfo (const ULONG_PTR addr)
 

Protected Member Functions

bool FreeSymbols ()
 

Protected Attributes

HANDLE hProcess
 
bool isInit
 

Detailed Description

Definition at line 7 of file process_symbols.h.

Constructor & Destructor Documentation

◆ ProcessSymbolsManager()

ProcessSymbolsManager::ProcessSymbolsManager ( )
inline

Definition at line 10 of file process_symbols.h.

◆ ~ProcessSymbolsManager()

ProcessSymbolsManager::~ProcessSymbolsManager ( )
inline

Definition at line 15 of file process_symbols.h.

Here is the call graph for this function:

Member Function Documentation

◆ dumpSymbolInfo()

bool ProcessSymbolsManager::dumpSymbolInfo ( const ULONG_PTR addr)
inline

Definition at line 58 of file process_symbols.h.

◆ FreeSymbols()

bool ProcessSymbolsManager::FreeSymbols ( )
inlineprotected

Definition at line 82 of file process_symbols.h.

◆ funcNameFromAddr()

std::string ProcessSymbolsManager::funcNameFromAddr ( const ULONG_PTR addr)
inline

Definition at line 42 of file process_symbols.h.

◆ InitSymbols()

bool ProcessSymbolsManager::InitSymbols ( HANDLE _hProcess)
inline

Definition at line 20 of file process_symbols.h.

◆ IsInitialized()

bool ProcessSymbolsManager::IsInitialized ( )
inline

Definition at line 35 of file process_symbols.h.

Member Data Documentation

◆ hProcess

HANDLE ProcessSymbolsManager::hProcess
protected

Definition at line 92 of file process_symbols.h.

◆ isInit

bool ProcessSymbolsManager::isInit
protected

Definition at line 93 of file process_symbols.h.


The documentation for this class was generated from the following file: