![]() |
PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
Variables | |
| params = pesieve.t_params() | |
| pid | |
| dotnet_policy | |
| imprec_mode | |
| quiet | |
| out_filter | |
| no_hooks | |
| shellcode | |
| obfuscated | |
| threads | |
| iat | |
| data | |
| minidump | |
| dump_mode | |
| json_output | |
| make_reflection | |
| use_cache | |
| json_lvl | |
| results_filter | |
| output_dir | |
| str | ignored = b'ignored1;ignored2' |
| modules_ignored | |
| length | |
| buffer | |
| pattern_file | |
| report | |
| json | |
| out_size | |
| demo.params = pesieve.t_params() |