PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
Static Public Attributes | |
int | OBFUSC_NONE = 0 |
int | OBFUSC_STRONG_ENC = 1 |
int | OBFUSC_WEAK_ENC = 2 |
int | OBFUSC_ANY = 3 |
int | OBFUSC_COUNT = 4 |
Definition at line 35 of file pesieve.py.
|
static |
Definition at line 39 of file pesieve.py.
|
static |
Definition at line 40 of file pesieve.py.
|
static |
Definition at line 36 of file pesieve.py.
|
static |
Definition at line 37 of file pesieve.py.
|
static |
Definition at line 38 of file pesieve.py.