![]() |
PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
The main file of PE-sieve built as an EXE. More...
#include <windows.h>#include <psapi.h>#include <sstream>#include <fstream>#include "pe_sieve.h"#include "params.h"#include "utils/process_privilege.h"#include "params_info/pe_sieve_params_info.h"#include "utils/process_reflection.h"#include "utils/console_color.h"#include "color_scheme.h"Go to the source code of this file.
Functions | |
| void | print_report (const pesieve::ReportEx &report, const t_params args) |
| void | free_params (t_params &args) |
| int | main (int argc, char *argv[]) |
The main file of PE-sieve built as an EXE.
Definition in file main.cpp.
| void free_params | ( | t_params & | args | ) |
| int main | ( | int | argc, |
| char * | argv[] ) |
| void print_report | ( | const pesieve::ReportEx & | report, |
| const t_params | args ) |