PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::util::BasicBuffer, including all inherited members.
BasicBuffer() | pesieve::util::BasicBuffer | inline |
data | pesieve::util::BasicBuffer | |
data_size | pesieve::util::BasicBuffer | protected |
getData(bool trimmed=false) const | pesieve::util::BasicBuffer | inline |
getDataSize(bool trimmed=false) const | pesieve::util::BasicBuffer | inline |
getStartOffset(bool trimmed) const | pesieve::util::BasicBuffer | inline |
isFilled() | pesieve::util::BasicBuffer | inline |
padding | pesieve::util::BasicBuffer | protected |
real_end | pesieve::util::BasicBuffer | protected |
real_start | pesieve::util::BasicBuffer | protected |
trim() | pesieve::util::BasicBuffer | inline |