PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
Loading...
Searching...
No Matches
pe_sieve_params_info.h
Go to the documentation of this file.
1#pragma once
2
3#include <iostream>
4#include <pe_sieve_types.h>
5
6namespace pesieve {
7 std::string translate_dump_mode(const DWORD dump_mode);
8 std::string translate_out_filter(const pesieve::t_output_filter o_filter);
9 std::string translate_data_mode(const pesieve::t_data_scan_mode &mode);
10 std::string translate_imprec_mode(const pesieve::t_imprec_mode imprec_mode);
13 std::string translate_json_level(const pesieve::t_json_level &mode);
14 std::string translate_shellc_mode(const pesieve::t_shellc_mode& mode);
15 std::string shellc_mode_mode_to_id(const pesieve::t_shellc_mode& mode);
16
17 std::string translate_obfusc_mode(const pesieve::t_obfusc_mode& mode);
18 std::string obfusc_mode_mode_to_id(const pesieve::t_obfusc_mode& mode);
19
20 std::string dump_mode_to_id(const DWORD dump_mode);
21 std::string imprec_mode_to_id(const pesieve::t_imprec_mode imprec_mode);
22};
23
std::string shellc_mode_mode_to_id(const pesieve::t_shellc_mode &mode)
std::string translate_iat_scan_mode(const pesieve::t_iat_scan_mode mode)
std::string translate_data_mode(const pesieve::t_data_scan_mode &mode)
std::string imprec_mode_to_id(const pesieve::t_imprec_mode imprec_mode)
std::string translate_obfusc_mode(const pesieve::t_obfusc_mode &mode)
std::string translate_dump_mode(const DWORD dump_mode)
std::string obfusc_mode_mode_to_id(const pesieve::t_obfusc_mode &mode)
std::string dump_mode_to_id(const DWORD dump_mode)
std::string translate_json_level(const pesieve::t_json_level &mode)
std::string translate_out_filter(const pesieve::t_output_filter o_filter)
std::string translate_imprec_mode(const pesieve::t_imprec_mode imprec_mode)
std::string translate_dotnet_policy(const pesieve::t_dotnet_policy &mode)
std::string translate_shellc_mode(const pesieve::t_shellc_mode &mode)
The types used by PE-sieve API.