PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::ScannedModule, including all inherited members.
getEnd() const | pesieve::ScannedModule | inline |
getModName() const | pesieve::ScannedModule | inline |
getSize() | pesieve::ScannedModule | inline |
getStart() const | pesieve::ScannedModule | inline |
isSuspicious() const | pesieve::ScannedModule | inline |
ModulesInfo class | pesieve::ScannedModule | friend |
operator<(ScannedModule other) const | pesieve::ScannedModule | inlineprotected |
resize(size_t newSize) | pesieve::ScannedModule | inlineprotected |
ScannedModule(ULONGLONG _start, size_t _moduleSize) | pesieve::ScannedModule | inlineprotected |
setSuspicious(bool _is_suspicious) | pesieve::ScannedModule | inlineprotected |
start | pesieve::ScannedModule | protected |
~ScannedModule() | pesieve::ScannedModule | inlineprotected |