PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::ThreadScanner, including all inherited members.
analyzeCallStack(IN const std::vector< ULONGLONG > &stack_frame, IN OUT ctx_details &cDetails) | pesieve::ThreadScanner | protected |
checkReturnAddrIntegrity(IN const std::vector< ULONGLONG > &callStack) | pesieve::ThreadScanner | protected |
exportsMap | pesieve::ThreadScanner | protected |
fetchThreadCtxDetails(IN HANDLE hProcess, IN HANDLE hThread, OUT ctx_details &c) | pesieve::ThreadScanner | protected |
fillAreaStats(ThreadScanReport *my_report) | pesieve::ThreadScanner | protected |
fillCallStackInfo(IN HANDLE hProcess, IN HANDLE hThread, IN LPVOID ctx, IN OUT ctx_details &cDetails) | pesieve::ThreadScanner | protected |
info | pesieve::ThreadScanner | protected |
isAddrInShellcode(ULONGLONG addr) | pesieve::ThreadScanner | protected |
isReflection | pesieve::ThreadScanner | protected |
modulesInfo | pesieve::ThreadScanner | protected |
printResolvedAddr(ULONGLONG addr) | pesieve::ThreadScanner | protected |
printThreadInfo(const util::thread_info &threadi) | pesieve::ThreadScanner | protected |
ProcessFeatureScanner(HANDLE _processHandle) | pesieve::ProcessFeatureScanner | inline |
processHandle | pesieve::ProcessFeatureScanner | protected |
reportSuspiciousAddr(ThreadScanReport *my_report, ULONGLONG susp_addr) | pesieve::ThreadScanner | protected |
scanRemote() | pesieve::ThreadScanner | virtual |
scanRemoteThreadCtx(HANDLE hThread, ThreadScanReport *my_report) | pesieve::ThreadScanner | protected |
symbols | pesieve::ThreadScanner | protected |
ThreadScanner(HANDLE hProc, bool _isReflection, const util::thread_info &_info, ModulesInfo &_modulesInfo, peconv::ExportsMapper *_exportsMap, ProcessSymbolsManager *_symbols) | pesieve::ThreadScanner | inline |
~ProcessFeatureScanner() | pesieve::ProcessFeatureScanner | inlinevirtual |