PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::ProcessDumpReport, including all inherited members.
appendReport(ModuleDumpReport *report) | pesieve::ProcessDumpReport | inline |
countDumped() const | pesieve::ProcessDumpReport | inline |
countTotal() const | pesieve::ProcessDumpReport | inline |
deleteModuleReports() | pesieve::ProcessDumpReport | inlineprotected |
getPid() const | pesieve::ProcessDumpReport | inline |
hasModule(const ULONGLONG modBase, const size_t modSize) const | pesieve::ProcessDumpReport | inline |
isFilled() const | pesieve::ProcessDumpReport | inline |
list_dumped_modules(size_t level) const | pesieve::ProcessDumpReport | protected |
minidumpPath | pesieve::ProcessDumpReport | |
moduleReports | pesieve::ProcessDumpReport | protected |
outputDir | pesieve::ProcessDumpReport | |
pid | pesieve::ProcessDumpReport | protected |
ProcessDumpReport(DWORD _pid) | pesieve::ProcessDumpReport | inline |
ResultsDumper class | pesieve::ProcessDumpReport | friend |
toJSON(std::stringstream &stream, size_t level) const | pesieve::ProcessDumpReport | virtual |
~ProcessDumpReport() | pesieve::ProcessDumpReport | inline |