PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Toggle main menu visibility
Main Page
Namespaces
Namespace List
Namespace Members
All
_
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Functions
_
b
c
d
e
f
g
h
i
l
m
n
o
p
q
r
s
t
v
w
Variables
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
w
Typedefs
Enumerations
Enumerator
c
h
i
p
s
t
Classes
Class List
Class Index
Class Hierarchy
Class Members
All
_
a
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
~
Functions
_
a
b
c
d
e
f
g
h
i
l
m
n
o
p
r
s
t
u
v
w
~
Variables
_
a
b
c
d
e
f
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Typedefs
Enumerations
Enumerator
i
o
r
s
Related Symbols
Files
File List
File Members
All
a
b
c
d
e
f
g
h
i
j
l
m
o
p
r
s
t
u
Functions
Variables
Typedefs
Enumerations
Enumerator
j
o
p
r
s
Macros
c
d
e
g
h
i
l
m
o
p
r
u
•
All
Classes
Namespaces
Files
Functions
Variables
Typedefs
Enumerations
Enumerator
Friends
Macros
Pages
Loading...
Searching...
No Matches
Here is a list of all file members with links to the files they belong to:
- a -
alloc_strparam() :
params.h
- b -
bool :
pe_sieve_types.h
- c -
cache :
module_data.cpp
CALC_PAGE_STATS :
workingset_scanner.h
CHARSET_SIZE :
stats_analyzer.cpp
CODE_RULE :
stats_analyzer.h
- d -
DEFAULT_BASE :
results_dumper.cpp
DIR_SEPARATOR :
results_dumper.cpp
DllMain() :
dll_main.cpp
- e -
ENTROPY_CODE_TRESHOLD :
stats_analyzer.cpp
ENTROPY_DATA_TRESHOLD :
stats_analyzer.cpp
ENTROPY_ENC_TRESHOLD :
stats_analyzer.cpp
ENTROPY_STRONG_ENC_TRESHOLD :
stats_analyzer.cpp
ENTROPY_TRESHOLD :
thread_scanner.cpp
enum_stack_thread() :
thread_scanner.cpp
ERROR_SCAN_FAILURE :
pe_sieve_types.h
- f -
free_params() :
main.cpp
free_strparam() :
params.h
- g -
g_Matcher :
pe_sieve.cpp
,
workingset_scanner.cpp
g_SyscallTable :
pe_sieve.cpp
,
thread_scanner.cpp
g_System32Path :
path_converter.cpp
g_Syswow64Path :
path_converter.cpp
get_full_path() :
path_util.cpp
get_page_details() :
thread_scanner.cpp
get_thunk_at_rva() :
iat_scanner.cpp
GLOBALROOT_NAME :
path_converter.cpp
- h -
HPSS :
process_reflection.cpp
- i -
INVALID_OFFSET :
artefact_scanner.h
INVALID_SYSCALL :
threads_util.h
is_device_path() :
path_converter.cpp
IS_ENDLINE :
strings_util.h
IS_PRINTABLE :
strings_util.h
- j -
JSON_BASIC :
pe_sieve_types.h
JSON_DETAILS :
pe_sieve_types.h
JSON_DETAILS2 :
pe_sieve_types.h
JSON_LVL_COUNT :
pe_sieve_types.h
- l -
LIB_NAME :
pe_sieve_api.cpp
LONG_PATH_PREFIX :
path_converter.cpp
- m -
main() :
main.cpp
mask :
workingset_enum.cpp
MASK_TO_DWORD :
iat_finder.h
MIN_THUNKS_COUNT :
imp_reconstructor.cpp
- o -
OBFUSC_ANY :
pe_sieve_types.h
OBFUSC_COUNT :
pe_sieve_types.h
OBFUSC_NONE :
pe_sieve_types.h
OBFUSC_STRONG_ENC :
pe_sieve_types.h
OBFUSC_WEAK_ENC :
pe_sieve_types.h
OUT_FILTERS_COUNT :
pe_sieve_types.h
OUT_FULL :
pe_sieve_types.h
OUT_NO_DIR :
pe_sieve_types.h
OUT_NO_DUMPS :
pe_sieve_types.h
OUT_PADDED :
format_util.h
- p -
PAGE_SIZE :
workingset_enum.h
PARAM_DATA :
params.h
PARAM_DIR :
params.h
PARAM_DOTNET_POLICY :
params.h
PARAM_DUMP_MODE :
params.h
PARAM_IAT :
params.h
PARAM_IMP_REC :
params.h
PARAM_JSON :
params.h
PARAM_JSON_LVL :
params.h
PARAM_LIST_SEPARATOR :
pe_sieve_types.h
PARAM_MINIDUMP :
params.h
PARAM_MODULES_IGNORE :
params.h
PARAM_OBFUSCATED :
params.h
PARAM_OUT_FILTER :
params.h
PARAM_PATTERN :
params.h
PARAM_PID :
params.h
PARAM_QUIET :
params.h
PARAM_REBASE :
params.h
PARAM_REFLECTION :
params.h
PARAM_RESULTS_FILTER :
params.h
PARAM_SHELLCODE :
params.h
PARAM_STRING :
pe_sieve_types.h
PARAM_THREADS :
params.h
PATTERN_NOT_FOUND :
artefacts_util.h
PE_DATA_COUNT :
pe_sieve_types.h
PE_DATA_NO_SCAN :
pe_sieve_types.h
PE_DATA_SCAN_ALWAYS :
pe_sieve_types.h
PE_DATA_SCAN_DOTNET :
pe_sieve_types.h
PE_DATA_SCAN_INACCESSIBLE :
pe_sieve_types.h
PE_DATA_SCAN_INACCESSIBLE_ONLY :
pe_sieve_types.h
PE_DATA_SCAN_NO_DEP :
pe_sieve_types.h
PE_DNET_COUNT :
pe_sieve_types.h
PE_DNET_NONE :
pe_sieve_types.h
PE_DNET_SKIP_ALL :
pe_sieve_types.h
PE_DNET_SKIP_HOOKS :
pe_sieve_types.h
PE_DNET_SKIP_MAPPING :
pe_sieve_types.h
PE_DNET_SKIP_SHC :
pe_sieve_types.h
PE_DUMP_AUTO :
pe_sieve_types.h
PE_DUMP_MODES_COUNT :
pe_sieve_types.h
PE_DUMP_REALIGN :
pe_sieve_types.h
PE_DUMP_UNMAP :
pe_sieve_types.h
PE_DUMP_VIRTUAL :
pe_sieve_types.h
PE_IATS_ALL_SYS_FILTERED :
pe_sieve_types.h
PE_IATS_CLEAN_SYS_FILTERED :
pe_sieve_types.h
PE_IATS_MODES_COUNT :
pe_sieve_types.h
PE_IATS_NONE :
pe_sieve_types.h
PE_IATS_UNFILTERED :
pe_sieve_types.h
PE_IMPREC_AUTO :
pe_sieve_types.h
PE_IMPREC_MODES_COUNT :
pe_sieve_types.h
PE_IMPREC_NONE :
pe_sieve_types.h
PE_IMPREC_REBUILD0 :
pe_sieve_types.h
PE_IMPREC_REBUILD1 :
pe_sieve_types.h
PE_IMPREC_REBUILD2 :
pe_sieve_types.h
PE_IMPREC_UNERASE :
pe_sieve_types.h
PE_NOT_FOUND :
artefact_scanner.h
PESIEVE_API :
pe_sieve_api.h
PESIEVE_API_FUNC :
pe_sieve_api.h
PESIEVE_DETECTED :
pe_sieve_return_codes.h
PESIEVE_ERROR :
pe_sieve_return_codes.h
PESIEVE_EXPORTS :
dll_main.cpp
,
pe_sieve_api.cpp
PESieve_help() :
pe_sieve_api.h
,
pe_sieve_api.cpp
PESIEVE_INFO :
pe_sieve_return_codes.h
PESIEVE_MAJOR_VERSION :
pe_sieve_ver_short.h
PESIEVE_MICRO_VERSION :
pe_sieve_ver_short.h
PESIEVE_MINOR_VERSION :
pe_sieve_ver_short.h
PESIEVE_NOT_DETECTED :
pe_sieve_return_codes.h
PEsieve_params :
pe_sieve_api.h
PESIEVE_PATCH_VERSION :
pe_sieve_ver_short.h
PEsieve_report :
pe_sieve_api.h
PEsieve_rtype :
pe_sieve_api.h
PESieve_scan() :
pe_sieve_api.h
,
pe_sieve_api.cpp
PESieve_scan_ex() :
pe_sieve_api.h
,
pe_sieve_api.cpp
PESieve_version :
pe_sieve_api.h
,
pe_sieve_api.cpp
PESIEVE_VERSION_STR :
pe_sieve_ver_short.h
print_report() :
main.cpp
,
pe_sieve_api.cpp
- r -
REPORT_ALL :
pe_sieve_types.h
REPORT_DUMPED :
pe_sieve_types.h
REPORT_NONE :
pe_sieve_types.h
REPORT_SCANNED :
pe_sieve_types.h
RTL_CLONE_PROCESS_FLAGS_CREATE_SUSPENDED :
process_reflection.cpp
RTL_CLONE_PROCESS_FLAGS_INHERIT_HANDLES :
process_reflection.cpp
RTL_CLONE_PROCESS_FLAGS_NO_SYNCHRONIZE :
process_reflection.cpp
- s -
set_non_suspicious() :
scanner.cpp
SHELLC_COUNT :
pe_sieve_types.h
SHELLC_NONE :
pe_sieve_types.h
SHELLC_PATTERNS :
pe_sieve_types.h
SHELLC_PATTERNS_AND_STATS :
pe_sieve_types.h
SHELLC_PATTERNS_OR_STATS :
pe_sieve_types.h
SHELLC_STATS :
pe_sieve_types.h
should_scan_context() :
thread_scanner.cpp
SHOW_ALL :
pe_sieve_types.h
SHOW_ERRORS :
pe_sieve_types.h
SHOW_NONE :
pe_sieve_types.h
SHOW_NOT_SUSPICIOUS :
pe_sieve_types.h
SHOW_SUCCESSFUL_ONLY :
pe_sieve_types.h
SHOW_SUSPICIOUS :
pe_sieve_types.h
SHOW_SUSPICIOUS_AND_ERRORS :
pe_sieve_types.h
- t -
t_data_scan_mode :
pe_sieve_types.h
t_dotnet_policy :
pe_sieve_types.h
t_dump_mode :
pe_sieve_types.h
t_iat_scan_mode :
pe_sieve_types.h
t_imprec_mode :
pe_sieve_types.h
t_json_level :
pe_sieve_types.h
t_obfusc_mode :
pe_sieve_types.h
t_output_filter :
pe_sieve_types.h
t_params :
pe_sieve_types.h
t_pesieve_res :
pe_sieve_return_codes.h
t_report :
pe_sieve_types.h
t_report_type :
pe_sieve_types.h
t_results_filter :
pe_sieve_types.h
t_shellc_mode :
pe_sieve_types.h
t_stack_enum_params :
thread_scanner.cpp
translate_integrity_level() :
process_privilege.cpp
- u -
USE_PROCESS_SNAPSHOT :
process_reflection.h
USE_RTL_PROCESS_REFLECTION :
process_reflection.h
Generated by
1.13.2