![]() |
PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
| bindings | |
| include | |
| params_info | |
| postprocessors | |
| scanners | |
| stats | |
| utils | |
| color_scheme.h | |
| dll_main.cpp | The main file of PE-sieve built as a DLL |
| main.cpp | The main file of PE-sieve built as an EXE |
| params.h | |
| pe_sieve.cpp | |
| pe_sieve.h | The root of the PE-sieve scanner |
| pe_sieve_api.cpp | |
| pe_sieve_report.h | The final report produced by PE-sieve |
| pe_sieve_ver_short.h | |
| resources.h |