PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Toggle main menu visibility
Main Page
Namespaces
Namespace List
Namespace Members
All
_
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Functions
_
b
c
d
e
f
g
h
i
l
m
n
o
p
q
r
s
t
v
w
Variables
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
w
Typedefs
Enumerations
Enumerator
c
h
i
p
s
t
Classes
Class List
Class Index
Class Hierarchy
Class Members
All
_
a
b
c
d
e
f
g
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
~
Functions
_
a
b
c
d
e
f
g
h
i
l
m
n
o
p
r
s
t
u
v
w
~
Variables
_
a
b
c
d
e
f
h
i
j
l
m
n
o
p
q
r
s
t
u
v
w
Typedefs
Enumerations
Enumerator
i
o
r
s
Related Symbols
Files
File List
File Members
All
a
b
c
d
e
f
g
h
i
j
l
m
o
p
r
s
t
u
Functions
Variables
Typedefs
Enumerations
Enumerator
j
o
p
r
s
Macros
c
d
e
g
h
i
l
m
o
p
r
u
•
All
Classes
Namespaces
Files
Functions
Variables
Typedefs
Enumerations
Enumerator
Friends
Macros
Pages
Loading...
Searching...
No Matches
Here is a list of all namespace functions with links to the namespace documentation for each function:
- _ -
_get_process_DEP_policy() :
pesieve::util
_get_system_DEP_policy() :
pesieve::util
- b -
BOOL() :
pesieve::util
- c -
calc_import_table_size() :
pesieve
calc_nt_hdr_offset() :
pesieve::util
calc_offset() :
pesieve::util
calc_sec_hdrs_offset() :
pesieve::util
calcShannonEntropy() :
pesieve::stats
can_make_process_reflection() :
pesieve::util
check_access_denied() :
pesieve
checkRatios() :
pesieve
convert_to_peconv_dump_mode() :
pesieve
convert_to_win32_path() :
pesieve::util
convert_to_wow64_path() :
pesieve::util
count_section_hdrs() :
pesieve::util
count_workingset_entries() :
pesieve::util
countFoundStrings() :
pesieve
create_dir_recursively() :
pesieve::util
- d -
device_path_to_win32_path() :
pesieve::util
dir_exists() :
pesieve::util
dump_mode_to_id() :
pesieve
dump_report_to_json() :
pesieve
DWORD() :
pesieve::util
- e -
enum_modules() :
pesieve::util
enum_workingset() :
pesieve::util
err_report_to_json() :
pesieve
escape_path_separators() :
pesieve::util
expand_path() :
pesieve::util
extract_from_dll() :
pesieve::util
extract_syscall_table() :
pesieve::util
extract_syscalls() :
pesieve::util
- f -
fetch_threads_by_snapshot() :
pesieve::util
fetch_threads_info() :
pesieve::util
fetchPeakValues() :
pesieve::stats
fill_iat() :
pesieve
fillCodeStrings() :
pesieve::stats
find_first_import_descriptor() :
pesieve
find_iat() :
pesieve
find_import_table() :
pesieve
find_import_table_tpl() :
pesieve
find_pattern() :
pesieve::util
first_different() :
pesieve
- g -
generateHistogram() :
pesieve::stats
get_buffer_space_at() :
pesieve
get_current_color() :
pesieve::util
get_dump_mode_name() :
pesieve
get_first_section() :
pesieve::util
get_imprec_res_name() :
pesieve
get_integrity_level() :
pesieve::util
get_kernel32_hndl() :
pesieve::util
get_longest_func_name() :
pesieve
get_module_file_name() :
pesieve
get_next_commited_region() :
pesieve::util
get_number() :
pesieve::util
get_or_load_module() :
pesieve::util
get_payload_ext() :
pesieve
get_subpath_ptr() :
pesieve::util
get_system_drive() :
pesieve::util
getMostFrequentValue() :
pesieve::stats
getMostFrequentValues() :
pesieve::stats
getPrintableRatio() :
pesieve::stats
getValRatio() :
pesieve
- h -
hexdumpValue() :
pesieve::stats
hexdumpValues() :
pesieve::stats
- i -
imprec_mode_to_id() :
pesieve
indicator_to_str() :
pesieve
info() :
pesieve
init() :
pesieve
init_32_patterns() :
pesieve
init_64_patterns() :
pesieve
init_syspaths() :
pesieve::util
is_32bit_code() :
pesieve::util
is_64bit_code() :
pesieve::util
is_by_patterns() :
pesieve
is_by_stats() :
pesieve
is_code() :
pesieve::util
is_cstr_equal() :
pesieve::util
is_current_wow64() :
pesieve::util
is_dec() :
pesieve::util
is_DEP_enabled() :
pesieve::util
is_disk_relative() :
pesieve::util
is_executable() :
pesieve::util
is_hex() :
pesieve::util
is_in_list() :
pesieve::util
is_normal_inaccessible() :
pesieve::util
is_number() :
pesieve::util
is_process_64bit() :
pesieve::util
is_process_wow64() :
pesieve::util
is_readable() :
pesieve::util
is_relative() :
pesieve::util
is_running() :
pesieve
is_scanner_compatible() :
pesieve
is_shown_type() :
pesieve
is_thread_running() :
pesieve
is_valid_file_hdr() :
pesieve
is_valid_import_descriptor() :
pesieve
is_valid_section() :
pesieve
isAllPrintable() :
pesieve::stats
- l -
load_MiniDumpWriteDump() :
pesieve::util
load_PssCaptureFreeSnapshot() :
pesieve::util
load_RtlCreateProcessReflection() :
pesieve::util
ltrim() :
pesieve::util
- m -
make_dump() :
pesieve
make_dump_dir() :
pesieve
make_minidump() :
pesieve::util
make_process_reflection() :
pesieve::util
make_process_reflection1() :
pesieve::util
make_process_reflection2() :
pesieve::util
make_process_snapshot() :
pesieve::util
match_to_tag() :
pesieve
- n -
nt_create_file() :
pesieve::util
nt_retrieve_file_path() :
pesieve::util
NTSTATUS() :
pesieve::util
- o -
obfusc_mode_mode_to_id() :
pesieve
open_process() :
pesieve
overwrite_opt_hdr() :
pesieve
- p -
params_fields_to_JSON() :
pesieve
params_to_JSON() :
pesieve
PESieve_help() :
pesieve
PESieve_scan() :
pesieve
PESieve_scan_ex() :
pesieve
print_in_color() :
pesieve::util
print_scan_time() :
pesieve
print_scantime() :
pesieve::util
- q -
query_thread_details() :
pesieve::util
query_threads_details() :
pesieve::util
- r -
read_return_ptr() :
pesieve
refl_creator() :
pesieve::util
relative_to_absolute_path() :
pesieve::util
release_process_reflection() :
pesieve::util
release_process_snapshot() :
pesieve::util
remap_to_drive_letter() :
pesieve::util
replace_char() :
pesieve::util
report_to_json() :
pesieve
results_filter_to_id() :
pesieve
rtrim() :
pesieve::util
- s -
scan_and_dump() :
pesieve
scan_report_to_json() :
pesieve
scan_report_to_string() :
pesieve
search_till_pattern() :
pesieve
set_debug_privilege() :
pesieve::util
set_privilege() :
pesieve::util
shellc_mode_mode_to_id() :
pesieve
shift_artefacts() :
pesieve
string_to_list() :
pesieve::util
strip_prefix() :
pesieve::util
- t -
to_lowercase() :
pesieve::util
translate_data_mode() :
pesieve
translate_dotnet_policy() :
pesieve
translate_dump_mode() :
pesieve
translate_iat_scan_mode() :
pesieve
translate_imprec_mode() :
pesieve
translate_json_level() :
pesieve
translate_obfusc_mode() :
pesieve
translate_out_filter() :
pesieve
translate_results_filter() :
pesieve
translate_shellc_mode() :
pesieve
trim() :
pesieve::util
- v -
validate_hdrs_alignment() :
pesieve::util
validate_param_str() :
pesieve
valuesNotBelowMean() :
pesieve::stats
version_to_str() :
pesieve
- w -
wow64_disable_fs_redirection() :
pesieve::util
wow64_get_thread_context() :
pesieve::util
wow64_revert_fs_redirection() :
pesieve::util
Generated by
1.13.2