![]() |
PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
This is the complete list of members for pesieve::util::ProcessRefl, including all inherited members.
| hReflHndl | pesieve::util::ProcessRefl | |
| ProcessRefl(HANDLE _hReflHndl, HANDLE _snapshot=NULL) | pesieve::util::ProcessRefl | inline |
| releaseReflectedHndl() | pesieve::util::ProcessRefl | |
| snapshot | pesieve::util::ProcessRefl | |
| ~ProcessRefl() | pesieve::util::ProcessRefl | virtual |