PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
pe_reconstructor.cpp File Reference
#include "pe_reconstructor.h"
#include "../utils/workingset_enum.h"
#include <fstream>

Go to the source code of this file.

Namespaces

namespace  pesieve
 

Functions

bool pesieve::shift_artefacts (PeArtefacts &artefacts, size_t shift_size)