hasherezade/pe-sieve
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
C++BSD-2-Clause
Issues
- 4
x64 build version 0.4.0.1 silently crashes
#132 opened by greenozon - 1
Import reconstruction misses some entries
#131 opened by hasherezade - 3
ModuleData not properly initialized
#130 opened by Ph3r0X1337 - 1
Query on supported architectures
#129 opened by sridhard - 6
Exe crashes after dump
#125 opened by Yehh22 - 3
- 1
- 4
Need help with PeSieve
#123 opened by WiltedDeath - 5
Rust Bindings
#114 opened by 0x4ndy - 2
Problem with VirtualQueryEx
#120 opened by helloobaby - 1
Disk and memory PE headers comparision
#119 opened by rabbitstack - 2
some question about source code
#117 opened by helloobaby - 8
Linking with libpe-sieve.a fails (MinGW)
#71 opened by hillu - 5
found Chrome.exe as suspicios
#106 opened by xblack199 - 5
- 0
Undetected 64 bit shellcode
#108 opened by hasherezade - 11
pe-sieve 0.3.4 API doesn't detect "Implanted" and "Implanted PE" + feature request.
#104 opened by terrybr - 4
- 2
Lots of compiler warnings
#64 opened by FuccDucc - 2
When i open pe-sieve the program runs but it says on the end: press any key to continue, and it closes, what is that?
#87 opened by Robi1969 - 1
Process overwriting
#103 opened by MariasStory - 3
Patch analyze bug?
#102 opened by luciouskami - 8
- 2
- 0
- 0
Blind spot in the IAT hooks scan
#92 opened by hasherezade - 9
Recognize Virtual Table hooks
#88 opened by hasherezade - 4
Lower down the number of disk operations
#94 opened by AndyWatterman - 2
Error in appending a new Import Table
#96 opened by hasherezade - 1
Overeager imports reconstruction
#97 opened by hasherezade - 0
Not scanning .NET data
#93 opened by hasherezade - 1
- 1
Improve detecting when to realign the payload
#90 opened by hasherezade - 1
- 1
- 1
- 1
Crash on import reconstruction
#84 opened by hasherezade - 2
using UPX are scanned that hdr_modified
#82 opened by muse117 - 1
enhacement
#74 opened by noamlima - 1
Broken detection of ASPack
#73 opened by hasherezade - 1
Broken detection of ASProtect
#66 opened by hasherezade - 0
- 12
- 1
Broken hexadecimal PID
#65 opened by hasherezade - 4
Could not read the remote PE
#58 opened by bartblaze - 1
Detect IAT patching
#57 opened by hasherezade - 8
- 1
- 1
We miss you on youtube... please come back.
#55 opened by pedroflor - 0
Silent mode still outputting information
#52 opened by Jack-McDowell