PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Toggle main menu visibility
Main Page
Namespaces
Namespace List
Namespace Members
All
_
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Functions
_
b
c
d
e
f
g
h
i
l
m
n
o
p
q
r
s
t
v
w
Variables
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
w
Typedefs
Enumerations
Enumerator
c
h
i
p
s
t
Classes
Class List
Class Index
Class Hierarchy
Class Members
All
_
a
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
~
Functions
_
a
b
c
d
e
f
g
h
i
l
m
n
o
p
r
s
t
u
v
w
~
Variables
_
a
b
c
d
e
f
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Typedefs
Enumerations
Enumerator
i
o
r
s
Related Symbols
Files
File List
File Members
All
a
b
c
d
e
f
g
h
i
j
l
m
o
p
r
s
t
u
Functions
Variables
Typedefs
Enumerations
Enumerator
j
o
p
r
s
Macros
c
d
e
g
h
i
l
m
o
p
r
u
•
All
Classes
Namespaces
Files
Functions
Variables
Typedefs
Enumerations
Enumerator
Friends
Macros
Pages
Loading...
Searching...
No Matches
Here is a list of all enum values with links to the classes they belong to:
- i -
IMP_ALREADY_OK :
pesieve::ImpReconstructor
IMP_DIR_FIXED :
pesieve::ImpReconstructor
IMP_FIXED :
pesieve::ImpReconstructor
IMP_NOT_FOUND :
pesieve::ImpReconstructor
IMP_REC0 :
pesieve::ImpReconstructor
IMP_REC1 :
pesieve::ImpReconstructor
IMP_REC2 :
pesieve::ImpReconstructor
IMP_REC_COUNT :
pesieve::ImpReconstructor
IMP_RECOVERY_ERROR :
pesieve::ImpReconstructor
IMP_RECOVERY_NOT_APPLICABLE :
pesieve::ImpReconstructor
IMP_RECOVERY_SKIPPED :
pesieve::ImpReconstructor
IMP_RECREATED_FILTER0 :
pesieve::ImpReconstructor
IMP_RECREATED_FILTER1 :
pesieve::ImpReconstructor
IMP_RECREATED_FILTER2 :
pesieve::ImpReconstructor
- o -
OP_CALL_DWORD :
pesieve::PatchAnalyzer
OP_JMP :
pesieve::PatchAnalyzer
OP_JMP_VIA_ADDR_B1 :
pesieve::PatchAnalyzer
OP_JMP_VIA_ADDR_B2 :
pesieve::PatchAnalyzer
OP_PUSH_DWORD :
pesieve::PatchAnalyzer
OP_SHORTJMP :
pesieve::PatchAnalyzer
- r -
REPORT_ARTEFACT_SCAN :
pesieve::ProcessScanReport
REPORT_CODE_SCAN :
pesieve::ProcessScanReport
REPORT_HEADERS_SCAN :
pesieve::ProcessScanReport
REPORT_IAT_SCAN :
pesieve::ProcessScanReport
REPORT_MAPPING_SCAN :
pesieve::ProcessScanReport
REPORT_MEMPAGE_SCAN :
pesieve::ProcessScanReport
REPORT_SKIPPED_SCAN :
pesieve::ProcessScanReport
REPORT_THREADS_SCAN :
pesieve::ProcessScanReport
REPORT_TYPES_COUNT :
pesieve::ProcessScanReport
REPORT_UNREACHABLE_SCAN :
pesieve::ProcessScanReport
RULE_CODE :
pesieve::RuleMatcher
RULE_ENCRYPTED :
pesieve::RuleMatcher
RULE_NONE :
pesieve::RuleMatcher
RULE_OBFUSCATED :
pesieve::RuleMatcher
RULE_TEXT :
pesieve::RuleMatcher
- s -
SECTION_NOT_MODIFIED :
pesieve::CodeScanReport
SECTION_PATCHED :
pesieve::CodeScanReport
SECTION_SCAN_ERR :
pesieve::CodeScanReport
SECTION_UNPACKED :
pesieve::CodeScanReport
Generated by
1.13.2