Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
48size_tgetMostFrequentValues(IN const std::map<size_t, std::set< T >> &frequencies, OUT std::set<T>& values, IN OPTIONAL size_t top = 0, IN OPTIONAL size_t maxDiff = 0)
49 {
50auto itr = frequencies.rbegin();
51if (itr == frequencies.rend()) {
52return 0;
53 }
54//the highest frequency
55constsize_t mFreq = itr->first;
56size_t prev = mFreq;
57for (size_t i = 0; i < top && itr != frequencies.rend(); ++itr, ++i) {
size_t getMostFrequentValues(IN const std::map< size_t, std::set< T > > &frequencies, OUT std::set< T > &values, IN OPTIONAL size_t top=0, IN OPTIONAL size_t maxDiff=0)