PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::PeSection, including all inherited members.
isContained(ULONGLONG field_start, size_t field_size) | pesieve::PeSection | inline |
isInitialized() | pesieve::PeSection | inline |
loadedSection | pesieve::PeSection | |
loadedSize | pesieve::PeSection | |
loadOriginal(ModuleData &modData, size_t section_number) | pesieve::PeSection | inlineprotected |
loadRemote(RemoteModuleData &remoteModData, size_t section_number) | pesieve::PeSection | inlineprotected |
PeSection(RemoteModuleData &remoteModData, size_t section_number) | pesieve::PeSection | inline |
PeSection(ModuleData &modData, size_t section_number) | pesieve::PeSection | inline |
rawSize | pesieve::PeSection | |
rva | pesieve::PeSection | |
unload() | pesieve::PeSection | inlineprotected |
~PeSection() | pesieve::PeSection | inline |