PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
#include <dump_report.h>
Public Member Functions | |
ModuleDumpReport (ULONGLONG module_start, size_t module_size) | |
virtual const bool | toJSON (std::stringstream &outs, size_t level) |
Public Attributes | |
ULONGLONG | moduleStart |
size_t | moduleSize |
bool | is_corrupt_pe |
bool | is_shellcode |
std::string | impRecMode |
bool | isReportDumped |
bool | isDumped |
std::string | mode_info |
std::string | dumpFileName |
std::string | hooksTagFileName |
std::string | patternsTagFileName |
std::string | impListFileName |
std::string | notRecoveredFileName |
std::string | iatHooksFileName |
Definition at line 16 of file dump_report.h.
Definition at line 20 of file dump_report.h.
Definition at line 7 of file dump_report.cpp.
std::string pesieve::ModuleDumpReport::dumpFileName |
Definition at line 38 of file dump_report.h.
std::string pesieve::ModuleDumpReport::hooksTagFileName |
Definition at line 39 of file dump_report.h.
std::string pesieve::ModuleDumpReport::iatHooksFileName |
Definition at line 43 of file dump_report.h.
std::string pesieve::ModuleDumpReport::impListFileName |
Definition at line 41 of file dump_report.h.
std::string pesieve::ModuleDumpReport::impRecMode |
Definition at line 34 of file dump_report.h.
bool pesieve::ModuleDumpReport::is_corrupt_pe |
Definition at line 32 of file dump_report.h.
bool pesieve::ModuleDumpReport::is_shellcode |
Definition at line 33 of file dump_report.h.
bool pesieve::ModuleDumpReport::isDumped |
Definition at line 36 of file dump_report.h.
bool pesieve::ModuleDumpReport::isReportDumped |
Definition at line 35 of file dump_report.h.
std::string pesieve::ModuleDumpReport::mode_info |
Definition at line 37 of file dump_report.h.
size_t pesieve::ModuleDumpReport::moduleSize |
Definition at line 31 of file dump_report.h.
ULONGLONG pesieve::ModuleDumpReport::moduleStart |
Definition at line 30 of file dump_report.h.
std::string pesieve::ModuleDumpReport::notRecoveredFileName |
Definition at line 42 of file dump_report.h.
std::string pesieve::ModuleDumpReport::patternsTagFileName |
Definition at line 40 of file dump_report.h.