PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
Static Public Attributes | List of all members
pesieve.t_iat_scan_mode Class Reference
Inheritance diagram for pesieve.t_iat_scan_mode:
Inheritance graph
[legend]

Static Public Attributes

int PE_IATS_NONE = 0
 
int PE_IATS_CLEAN_SYS_FILTERED = 1
 
int PE_IATS_ALL_SYS_FILTERED = 2
 
int PE_IATS_UNFILTERED = 3
 
int PE_IATS_MODES_COUNT = 4
 

Detailed Description

Definition at line 58 of file pesieve.py.

Member Data Documentation

◆ PE_IATS_ALL_SYS_FILTERED

int pesieve.t_iat_scan_mode.PE_IATS_ALL_SYS_FILTERED = 2
static

Definition at line 61 of file pesieve.py.

◆ PE_IATS_CLEAN_SYS_FILTERED

int pesieve.t_iat_scan_mode.PE_IATS_CLEAN_SYS_FILTERED = 1
static

Definition at line 60 of file pesieve.py.

◆ PE_IATS_MODES_COUNT

int pesieve.t_iat_scan_mode.PE_IATS_MODES_COUNT = 4
static

Definition at line 63 of file pesieve.py.

◆ PE_IATS_NONE

int pesieve.t_iat_scan_mode.PE_IATS_NONE = 0
static

Definition at line 59 of file pesieve.py.

◆ PE_IATS_UNFILTERED

int pesieve.t_iat_scan_mode.PE_IATS_UNFILTERED = 3
static

Definition at line 62 of file pesieve.py.


The documentation for this class was generated from the following file: