hasherezade/pe-sieve
@hasherezadeScans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
Stars
3,879
Forks
495
Language
C++
License
BSD-2-Clause
Last push
3 months ago
Related intel (0)
No related intel yet
This repo has not appeared in any of the sources the radar tracks. The collector runs on a schedule — check back once it covers this repo.