PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Toggle main menu visibility
Main Page
Namespaces
Namespace List
Namespace Members
All
_
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Functions
_
b
c
d
e
f
g
h
i
l
m
n
o
p
q
r
s
t
v
w
Variables
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
w
Typedefs
Enumerations
Enumerator
c
h
i
p
s
t
Classes
Class List
Class Index
Class Hierarchy
Class Members
All
_
a
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
~
Functions
_
a
b
c
d
e
f
g
h
i
l
m
n
o
p
r
s
t
u
v
w
~
Variables
_
a
b
c
d
e
f
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Typedefs
Enumerations
Enumerator
i
o
r
s
Related Symbols
Files
File List
File Members
All
a
b
c
d
e
f
g
h
i
j
l
m
o
p
r
s
t
u
Functions
Variables
Typedefs
Enumerations
Enumerator
j
o
p
r
s
Macros
c
d
e
g
h
i
l
m
o
p
r
u
•
All
Classes
Namespaces
Files
Functions
Variables
Typedefs
Enumerations
Enumerator
Friends
Macros
Pages
Loading...
Searching...
No Matches
Here is a list of all functions with links to the classes they belong to:
- c -
CachedModule() :
pesieve::CachedModule
calcImageSize() :
pesieve::ArtefactScanner
calcImgSize() :
pesieve::ArtefactScanner
,
pesieve::RemoteModuleData
calcPeBase() :
pesieve::ArtefactScanner
calcPopulationStandardDeviation() :
pesieve::stats::StdDeviationCalc
calcPopulationVariance() :
pesieve::stats::StdDeviationCalc
calcRemoteImgSize() :
pesieve::PeBuffer
calcSampleStandardDeviation() :
pesieve::stats::StdDeviationCalc
calcSampleVariance() :
pesieve::stats::StdDeviationCalc
callstackToJSON() :
pesieve::ThreadScanReport
checkAreaContent() :
pesieve::WorkingSetScanner
checkForHookedExports() :
pesieve::PatchList
checkReturnAddrIntegrity() :
pesieve::ThreadScanner
choosePreferredFunctionName() :
pesieve::ThreadScanner
ChunkStats() :
pesieve::ChunkStats
CodeMatcher() :
pesieve::CodeMatcher
CodeScanner() :
pesieve::CodeScanner
CodeScanReport() :
pesieve::CodeScanReport
copy() :
pesieve::util::ByteBuffer
count() :
pesieve::ModulesInfo
countDumped() :
pesieve::ProcessDumpReport
countHdrsReplaced() :
pesieve::ProcessScanReport
countHooked() :
pesieve::IATScanReport
countInaccessibleSections() :
pesieve::CodeScanReport
countResultsPerType() :
pesieve::ProcessScanReport
countSectionsWithStatus() :
pesieve::CodeScanReport
countSuspiciousPerType() :
pesieve::ProcessScanReport
countThunks() :
pesieve::IATBlock
countTotal() :
pesieve::ProcessDumpReport
countUnpackedSections() :
pesieve::CodeScanReport
Generated by
1.13.2