PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
► bindings | |
► include | |
► params_info | |
► postprocessors | |
► scanners | |
► stats | |
► utils | |
color_scheme.h | |
dll_main.cpp | The main file of PE-sieve built as a DLL |
main.cpp | The main file of PE-sieve built as an EXE |
params.h | |
pe_sieve.cpp | |
pe_sieve.h | The root of the PE-sieve scanner |
pe_sieve_api.cpp | |
pe_sieve_report.h | The final report produced by PE-sieve |
pe_sieve_ver_short.h | |
resources.h |