PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::AreaStats, including all inherited members.
_appendVal(BYTE val)=0 | pesieve::AreaStats | protectedpure virtual |
appendVal(BYTE val) | pesieve::AreaStats | inline |
area_size | pesieve::AreaStats | protected |
area_start | pesieve::AreaStats | protected |
AreaStats() | pesieve::AreaStats | inline |
AreaStatsCalculator class | pesieve::AreaStats | friend |
fieldsToJSON(std::stringstream &outs, size_t level)=0 | pesieve::AreaStats | pure virtual |
fillSettings(StatsSettings *_settings) | pesieve::AreaStats | inlinevirtual |
isFilled() const | pesieve::AreaStats | inline |
setStartOffset(size_t _area_start) | pesieve::AreaStats | inline |
summarize()=0 | pesieve::AreaStats | pure virtual |
toJSON(std::stringstream &outs, size_t level) | pesieve::AreaStats | inlinevirtual |