PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Toggle main menu visibility
Main Page
Namespaces
Namespace List
Namespace Members
All
_
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Functions
_
b
c
d
e
f
g
h
i
l
m
n
o
p
q
r
s
t
v
w
Variables
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
w
Typedefs
Enumerations
Enumerator
c
h
i
p
s
t
Classes
Class List
Class Index
Class Hierarchy
Class Members
All
_
a
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
~
Functions
_
a
b
c
d
e
f
g
h
i
l
m
n
o
p
r
s
t
u
v
w
~
Variables
_
a
b
c
d
e
f
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Typedefs
Enumerations
Enumerator
i
o
r
s
Related Symbols
Files
File List
File Members
All
a
b
c
d
e
f
g
h
i
j
l
m
o
p
r
s
t
u
Functions
Variables
Typedefs
Enumerations
Enumerator
j
o
p
r
s
Macros
c
d
e
g
h
i
l
m
o
p
r
u
•
All
Classes
Namespaces
Files
Functions
Variables
Typedefs
Enumerations
Enumerator
Friends
Macros
Pages
Loading...
Searching...
No Matches
Here is a list of all variables with links to the classes they belong to:
- s -
scan_report :
pesieve::ReportEx
scanned :
report
sec_count :
pesieve::ArtefactScanner::ArtefactsMapping
sec_hdr :
pesieve::ArtefactScanner::ArtefactsMapping
secCount :
pesieve::PeArtefacts
secHdrModified :
pesieve::HeadersScanReport
secHdrsOffset :
pesieve::PeArtefacts
sectionRVA :
pesieve::PatchAnalyzer
sectionToResult :
pesieve::CodeScanReport
settings :
pesieve::ChunkStats
shcCandidates :
pesieve::ThreadScanReport
SHELLC_COUNT :
pesieve.t_shellc_mode
SHELLC_NONE :
pesieve.t_shellc_mode
SHELLC_PATTERNS :
pesieve.t_shellc_mode
SHELLC_PATTERNS_AND_STATS :
pesieve.t_shellc_mode
SHELLC_PATTERNS_OR_STATS :
pesieve.t_shellc_mode
SHELLC_STATS :
pesieve.t_shellc_mode
shellcode :
params
SHOW_ALL :
pesieve.t_results_filter
SHOW_ERRORS :
pesieve.t_results_filter
SHOW_NONE :
pesieve.t_results_filter
SHOW_NOT_SUSPICIOUS :
pesieve.t_results_filter
SHOW_SUCCESSFUL_ONLY :
pesieve.t_results_filter
SHOW_SUSPICIOUS :
pesieve.t_results_filter
SHOW_SUSPICIOUS_AND_ERRORS :
pesieve.t_results_filter
size :
pesieve::_t_pattern
,
pesieve::ChunkStats
,
pesieve::util::_mem_region_info
skipped :
report
stack_ptr :
pesieve::ThreadScanReport
start :
pesieve::ScannedModule
start_addr :
pesieve::util::_thread_info
start_va :
pesieve::MemPageData
startOffset :
pesieve::IATThunksSeries
startRva :
pesieve::PatchList::Patch
state :
pesieve::util::_thread_info_ext
stats :
pesieve::ThreadScanReport
,
pesieve::WorkingSetScanReport
status :
pesieve::ElementScanReport
stop_va :
pesieve::MemPageData
storedFunc :
pesieve::IATScanReport
stringsCount :
pesieve::ChunkStats
susp_addr :
pesieve::ThreadScanReport
suspicious :
report
symbols :
pesieve::ProcessScanner
,
pesieve::ThreadScanner
sys_start_addr :
pesieve::util::_thread_info_ext
syscallToName :
pesieve::SyscallTable
SystemCallNumber :
pesieve::util::_THREAD_LAST_SYSCALL_INFORMATION
szModName :
pesieve::ModuleData
Generated by
1.13.2