PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::AreaEntropyStats, including all inherited members.
_appendVal(BYTE val) | pesieve::AreaEntropyStats | inlinevirtual |
appendVal(BYTE val) | pesieve::AreaStats | inline |
area_size | pesieve::AreaStats | protected |
area_start | pesieve::AreaStats | protected |
AreaEntropyStats() | pesieve::AreaEntropyStats | inline |
AreaEntropyStats(const AreaEntropyStats &p1) | pesieve::AreaEntropyStats | inline |
AreaStats() | pesieve::AreaStats | inline |
AreaStatsCalculator class | pesieve::AreaEntropyStats | friend |
entropy | pesieve::AreaEntropyStats | |
fieldsToJSON(std::stringstream &outs, size_t level) | pesieve::AreaEntropyStats | inlineprotectedvirtual |
fillSettings(StatsSettings *_settings) | pesieve::AreaStats | inlinevirtual |
histogram | pesieve::AreaEntropyStats | protected |
isFilled() const | pesieve::AreaStats | inline |
setStartOffset(size_t _area_start) | pesieve::AreaStats | inline |
summarize() | pesieve::AreaEntropyStats | inlinevirtual |
toJSON(std::stringstream &outs, size_t level) | pesieve::AreaStats | inlinevirtual |