![]() |
PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::IATThunksSeries, including all inherited members.
| endOffset | pesieve::IATThunksSeries | |
| fillNamesSpace(const BYTE *buf_start, size_t buf_size, DWORD bufRVA, bool is64b) | pesieve::IATThunksSeries | |
| funcCount() | pesieve::IATThunksSeries | inline |
| getDllName() | pesieve::IATThunksSeries | |
| getRvaToFuncMap() | pesieve::IATThunksSeries | inline |
| IATThunksSeries(DWORD start_offset) | pesieve::IATThunksSeries | inline |
| insert(DWORD rva, ULONGLONG funcAddr) | pesieve::IATThunksSeries | inline |
| isCovered() | pesieve::IATThunksSeries | inline |
| makeCoverage(IN const peconv::ExportsMapper *exportsMap) | pesieve::IATThunksSeries | |
| operator<(const IATThunksSeries &other) const | pesieve::IATThunksSeries | inline |
| sizeOfNamesSpace(bool is64b) | pesieve::IATThunksSeries | |
| startOffset | pesieve::IATThunksSeries | |
| ~IATThunksSeries() | pesieve::IATThunksSeries | inline |