PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
File List
Here is a list of all files with brief descriptions:
[detail level 123]
 
bindings
 
include
 
params_info
 
postprocessors
 
scanners
 
stats
 
utils
 
color_scheme.h
 
dll_main.cpp
The main file of PE-sieve built as a DLL
 
main.cpp
The main file of PE-sieve built as an EXE
 
params.h
 
pe_sieve.cpp
 
pe_sieve.h
The root of the PE-sieve scanner
 
pe_sieve_api.cpp
 
pe_sieve_report.h
The final report produced by PE-sieve
 
pe_sieve_ver_short.h
 
resources.h