PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::ModulesInfo, including all inherited members.
appendModule(ScannedModule *module) | pesieve::ModulesInfo | protected |
appendToModulesList(ModuleScanReport *report) | pesieve::ModulesInfo | |
count() | pesieve::ModulesInfo | inline |
deleteAll() | pesieve::ModulesInfo | protected |
findModuleContaining(ULONGLONG address, size_t size=0) const | pesieve::ModulesInfo | |
getModuleAt(ULONGLONG address) const | pesieve::ModulesInfo | |
getScannedSize(ULONGLONG start_address) const | pesieve::ModulesInfo | |
ModulesInfo(DWORD _pid) | pesieve::ModulesInfo | inline |
~ModulesInfo() | pesieve::ModulesInfo | inline |