PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
The main file of PE-sieve built as an EXE. More...
#include <windows.h>
#include <psapi.h>
#include <sstream>
#include <fstream>
#include "pe_sieve.h"
#include "params.h"
#include "utils/process_privilege.h"
#include "params_info/pe_sieve_params_info.h"
#include "utils/process_reflection.h"
#include "utils/console_color.h"
#include "color_scheme.h"
Go to the source code of this file.
Functions | |
void | print_report (const pesieve::ReportEx &report, const t_params args) |
void | free_params (t_params &args) |
int | main (int argc, char *argv[]) |
The main file of PE-sieve built as an EXE.
Definition in file main.cpp.
void free_params | ( | t_params & | args | ) |
int main | ( | int | argc, |
char * | argv[] ) |
void print_report | ( | const pesieve::ReportEx & | report, |
const t_params | args ) |