PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
File List
Here is a list of all files with brief descriptions:
[detail level 123]
  bindings
  include
  params_info
  postprocessors
  scanners
  stats
  utils
 color_scheme.h
 dll_main.cppThe main file of PE-sieve built as a DLL
 main.cppThe main file of PE-sieve built as an EXE
 params.h
 pe_sieve.cpp
 pe_sieve.hThe root of the PE-sieve scanner
 pe_sieve_api.cpp
 pe_sieve_report.hThe final report produced by PE-sieve
 pe_sieve_ver_short.h
 resources.h