PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::ThunkFoundCallback, including all inherited members.
shouldAcceptExport(ULONGLONG va, const peconv::ExportedFunc &exp)=0 | pesieve::ThunkFoundCallback | pure virtual |
shouldProcessVA(ULONGLONG va)=0 | pesieve::ThunkFoundCallback | pure virtual |
ThunkFoundCallback() | pesieve::ThunkFoundCallback | inline |