PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::IATThunksSeries, including all inherited members.
fillNamesSpace(const BYTE *buf_start, size_t buf_size, DWORD bufRVA, bool is64b) | pesieve::IATThunksSeries | |
getDllName() | pesieve::IATThunksSeries | |
getRvaToFuncMap() | pesieve::IATThunksSeries | inline |
IATThunksSeries(DWORD start_offset) | pesieve::IATThunksSeries | inline |
insert(DWORD rva, ULONGLONG funcAddr) | pesieve::IATThunksSeries | inline |
isCovered() | pesieve::IATThunksSeries | inline |
makeCoverage(IN const peconv::ExportsMapper *exportsMap) | pesieve::IATThunksSeries | |
operator<(const IATThunksSeries &other) const | pesieve::IATThunksSeries | inline |
sizeOfNamesSpace(bool is64b) | pesieve::IATThunksSeries | |
startOffset | pesieve::IATThunksSeries | |
~IATThunksSeries() | pesieve::IATThunksSeries | inline |