PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
pesieve::ThreadScanner Member List

This is the complete list of members for pesieve::ThreadScanner, including all inherited members.

enumStackFrames(IN HANDLE hProcess, IN HANDLE hThread, IN LPVOID ctx, IN OUT thread_ctx &c)pesieve::ThreadScannerprotected
exportsMappesieve::ThreadScannerprotected
fetchThreadCtx(IN HANDLE hProcess, IN HANDLE hThread, OUT thread_ctx &c)pesieve::ThreadScannerprotected
fillAreaStats(ThreadScanReport *my_report)pesieve::ThreadScannerprotected
FreeSymbols(HANDLE hProc)pesieve::ThreadScannerstatic
infopesieve::ThreadScannerprotected
InitSymbols(HANDLE hProc)pesieve::ThreadScannerstatic
isAddrInShellcode(ULONGLONG addr)pesieve::ThreadScannerprotected
isReflectionpesieve::ThreadScannerprotected
modulesInfopesieve::ThreadScannerprotected
ProcessFeatureScanner(HANDLE _processHandle)pesieve::ProcessFeatureScannerinline
processHandlepesieve::ProcessFeatureScannerprotected
reportSuspiciousAddr(ThreadScanReport *my_report, ULONGLONG susp_addr, thread_ctx &c)pesieve::ThreadScannerprotected
resolveAddr(ULONGLONG addr)pesieve::ThreadScannerprotected
scanRemote()pesieve::ThreadScannervirtual
ThreadScanner(HANDLE hProc, bool _isReflection, const util::thread_info &_info, ModulesInfo &_modulesInfo, peconv::ExportsMapper *_exportsMap)pesieve::ThreadScannerinline
~ProcessFeatureScanner()pesieve::ProcessFeatureScannerinlinevirtual