![]() |
PE-sieve
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
|
#include <process_reflection.h>
Public Member Functions | |
| ProcessRefl (HANDLE _hReflHndl, HANDLE _snapshot=NULL) | |
| virtual | ~ProcessRefl () |
| bool | releaseReflectedHndl () |
Public Attributes | |
| HANDLE | hReflHndl |
| HANDLE | snapshot |
Definition at line 11 of file process_reflection.h.
|
inline |
Definition at line 14 of file process_reflection.h.
|
virtual |
| bool pesieve::util::ProcessRefl::releaseReflectedHndl | ( | ) |
| HANDLE pesieve::util::ProcessRefl::hReflHndl |
Definition at line 23 of file process_reflection.h.
| HANDLE pesieve::util::ProcessRefl::snapshot |
Definition at line 24 of file process_reflection.h.