diff --git a/classpesieve_1_1_artefact_scanner.html b/classpesieve_1_1_artefact_scanner.html index aa362d37e..5ae01dcc5 100644 --- a/classpesieve_1_1_artefact_scanner.html +++ b/classpesieve_1_1_artefact_scanner.html @@ -1299,7 +1299,7 @@

- + diff --git a/classpesieve_1_1_artefact_scanner_a732749d6a208c45fad90e07f0c6da609_cgraph.map b/classpesieve_1_1_artefact_scanner_a732749d6a208c45fad90e07f0c6da609_cgraph.map index 5650185e9..4bff21ee3 100644 --- a/classpesieve_1_1_artefact_scanner_a732749d6a208c45fad90e07f0c6da609_cgraph.map +++ b/classpesieve_1_1_artefact_scanner_a732749d6a208c45fad90e07f0c6da609_cgraph.map @@ -3,7 +3,7 @@ - + diff --git a/classpesieve_1_1_artefact_scanner_a732749d6a208c45fad90e07f0c6da609_cgraph.png b/classpesieve_1_1_artefact_scanner_a732749d6a208c45fad90e07f0c6da609_cgraph.png index 425adec35..0dc80cdac 100644 Binary files a/classpesieve_1_1_artefact_scanner_a732749d6a208c45fad90e07f0c6da609_cgraph.png and b/classpesieve_1_1_artefact_scanner_a732749d6a208c45fad90e07f0c6da609_cgraph.png differ diff --git a/classpesieve_1_1_process_scanner.html b/classpesieve_1_1_process_scanner.html index a43a76219..c68a8ef88 100644 --- a/classpesieve_1_1_process_scanner.html +++ b/classpesieve_1_1_process_scanner.html @@ -358,7 +358,7 @@

- + @@ -1010,7 +1010,7 @@

- + diff --git a/classpesieve_1_1_process_scanner_a2058c6be1e628a7a46a1a5dd989c49ad_cgraph.map b/classpesieve_1_1_process_scanner_a2058c6be1e628a7a46a1a5dd989c49ad_cgraph.map index 2ccef121b..77c522be0 100644 --- a/classpesieve_1_1_process_scanner_a2058c6be1e628a7a46a1a5dd989c49ad_cgraph.map +++ b/classpesieve_1_1_process_scanner_a2058c6be1e628a7a46a1a5dd989c49ad_cgraph.map @@ -5,7 +5,7 @@ - + diff --git a/classpesieve_1_1_process_scanner_a2058c6be1e628a7a46a1a5dd989c49ad_cgraph.png b/classpesieve_1_1_process_scanner_a2058c6be1e628a7a46a1a5dd989c49ad_cgraph.png index 431ff3618..47b6f07d4 100644 Binary files a/classpesieve_1_1_process_scanner_a2058c6be1e628a7a46a1a5dd989c49ad_cgraph.png and b/classpesieve_1_1_process_scanner_a2058c6be1e628a7a46a1a5dd989c49ad_cgraph.png differ diff --git a/classpesieve_1_1_process_scanner_a8f5f9ef11d71f271adbb261efc4453f3_cgraph.map b/classpesieve_1_1_process_scanner_a8f5f9ef11d71f271adbb261efc4453f3_cgraph.map index c65b9e618..d79fe9ebf 100644 --- a/classpesieve_1_1_process_scanner_a8f5f9ef11d71f271adbb261efc4453f3_cgraph.map +++ b/classpesieve_1_1_process_scanner_a8f5f9ef11d71f271adbb261efc4453f3_cgraph.map @@ -3,7 +3,7 @@ - + diff --git a/classpesieve_1_1_process_scanner_a8f5f9ef11d71f271adbb261efc4453f3_cgraph.png b/classpesieve_1_1_process_scanner_a8f5f9ef11d71f271adbb261efc4453f3_cgraph.png index 5e0e0bc23..d6ad7e31c 100644 Binary files a/classpesieve_1_1_process_scanner_a8f5f9ef11d71f271adbb261efc4453f3_cgraph.png and b/classpesieve_1_1_process_scanner_a8f5f9ef11d71f271adbb261efc4453f3_cgraph.png differ diff --git a/classpesieve_1_1_thread_scanner.html b/classpesieve_1_1_thread_scanner.html index e0f68c9c7..c8e4cf335 100644 --- a/classpesieve_1_1_thread_scanner.html +++ b/classpesieve_1_1_thread_scanner.html @@ -161,7 +161,7 @@

Detailed Description

A scanner for threads Stack-scan inspired by the idea presented here: https://github.com/thefLink/Hunt-Sleeping-Beacons

-

Definition at line 122 of file thread_scanner.h.

+

Definition at line 123 of file thread_scanner.h.

Constructor & Destructor Documentation

◆ ThreadScanner()

@@ -210,7 +210,7 @@

-

Definition at line 124 of file thread_scanner.h.

+

Definition at line 125 of file thread_scanner.h.

@@ -288,7 +288,7 @@

-

Definition at line 229 of file thread_scanner.cpp.

+

Definition at line 230 of file thread_scanner.cpp.

Here is the call graph for this function:
@@ -333,7 +333,7 @@

-

Definition at line 336 of file thread_scanner.cpp.

+

Definition at line 337 of file thread_scanner.cpp.

Here is the call graph for this function:
@@ -408,7 +408,7 @@

-

Definition at line 194 of file thread_scanner.cpp.

+

Definition at line 195 of file thread_scanner.cpp.

Here is the call graph for this function:
@@ -445,7 +445,7 @@

-

Definition at line 263 of file thread_scanner.cpp.

+

Definition at line 264 of file thread_scanner.cpp.

Here is the call graph for this function:
@@ -482,7 +482,7 @@

-

Definition at line 275 of file thread_scanner.cpp.

+

Definition at line 276 of file thread_scanner.cpp.

Here is the call graph for this function:
@@ -519,7 +519,7 @@

-

Definition at line 305 of file thread_scanner.cpp.

+

Definition at line 306 of file thread_scanner.cpp.

Here is the call graph for this function:
@@ -562,7 +562,7 @@

-

Definition at line 349 of file thread_scanner.cpp.

+

Definition at line 350 of file thread_scanner.cpp.

Here is the call graph for this function:
@@ -604,7 +604,7 @@

pesieve::ProcessFeatureScanner.

-

Definition at line 398 of file thread_scanner.cpp.

+

Definition at line 399 of file thread_scanner.cpp.

Here is the call graph for this function:
@@ -644,7 +644,7 @@

-

Definition at line 146 of file thread_scanner.h.

+

Definition at line 147 of file thread_scanner.h.

@@ -668,7 +668,7 @@

-

Definition at line 144 of file thread_scanner.h.

+

Definition at line 145 of file thread_scanner.h.

@@ -692,7 +692,7 @@

-

Definition at line 143 of file thread_scanner.h.

+

Definition at line 144 of file thread_scanner.h.

@@ -716,7 +716,7 @@

-

Definition at line 145 of file thread_scanner.h.

+

Definition at line 146 of file thread_scanner.h.

@@ -740,7 +740,7 @@

-

Definition at line 147 of file thread_scanner.h.

+

Definition at line 148 of file thread_scanner.h.

diff --git a/doxygen_crawl.html b/doxygen_crawl.html index 5999d4ef1..21d2234ad 100644 --- a/doxygen_crawl.html +++ b/doxygen_crawl.html @@ -2490,11 +2490,12 @@ - + + diff --git a/functions_l.html b/functions_l.html index 08e494e03..2b3afac52 100644 --- a/functions_l.html +++ b/functions_l.html @@ -89,6 +89,7 @@
Here is a list of all class members with links to the classes they belong to:

- l -

    +
  • last_ret : pesieve::_ctx_details
  • lastStr : pesieve::ChunkStats
  • lastUsage : pesieve::CachedModule
  • length : _PARAM_STRING
  • diff --git a/functions_r.html b/functions_r.html index 38108353b..29f9a67f8 100644 --- a/functions_r.html +++ b/functions_r.html @@ -140,7 +140,6 @@

    - r -

    • resolveHooksTargets() : pesieve::ProcessScanner
    • resolveTarget() : pesieve::HookTargetResolver
    • ResultsDumper : pesieve::ProcessDumpReport, pesieve::ProcessScanReport, pesieve::ResultsDumper
    • -
    • ret_addr : pesieve::_ctx_details
    • returned_hndl : pesieve::util::t_refl_args
    • returned_pid : pesieve::util::t_refl_args
    • rip : pesieve::_ctx_details
    • diff --git a/functions_s.html b/functions_s.html index c6c6994f6..64a3743c4 100644 --- a/functions_s.html +++ b/functions_s.html @@ -129,6 +129,7 @@

      - s -

      • setSuspicious() : pesieve::ScannedModule
      • setTableInPe() : pesieve::ImportTableBuffer
      • settings : pesieve::ChunkStats
      • +
      • shcCandidates : pesieve::_ctx_details
      • SHELLC_COUNT : pesieve.t_shellc_mode
      • SHELLC_NONE : pesieve.t_shellc_mode
      • SHELLC_PATTERNS : pesieve.t_shellc_mode
      • diff --git a/functions_vars_l.html b/functions_vars_l.html index 9aa570f65..fca887d69 100644 --- a/functions_vars_l.html +++ b/functions_vars_l.html @@ -89,6 +89,7 @@
        Here is a list of all variables with links to the classes they belong to:

        - l -

          +
        • last_ret : pesieve::_ctx_details
        • lastStr : pesieve::ChunkStats
        • lastUsage : pesieve::CachedModule
        • length : _PARAM_STRING
        • diff --git a/functions_vars_r.html b/functions_vars_r.html index 48f232d77..272570b3b 100644 --- a/functions_vars_r.html +++ b/functions_vars_r.html @@ -108,7 +108,6 @@

          - r -

          • REPORT_NONE : pesieve.t_report_type
          • REPORT_SCANNED : pesieve.t_report_type
          • reportsByType : pesieve::ProcessScanReport
          • -
          • ret_addr : pesieve::_ctx_details
          • returned_hndl : pesieve::util::t_refl_args
          • returned_pid : pesieve::util::t_refl_args
          • rip : pesieve::_ctx_details
          • diff --git a/functions_vars_s.html b/functions_vars_s.html index b7d451cf7..84e6038c8 100644 --- a/functions_vars_s.html +++ b/functions_vars_s.html @@ -99,6 +99,7 @@

            - s -

            • sectionRVA : pesieve::PatchAnalyzer
            • sectionToResult : pesieve::CodeScanReport
            • settings : pesieve::ChunkStats
            • +
            • shcCandidates : pesieve::_ctx_details
            • SHELLC_COUNT : pesieve.t_shellc_mode
            • SHELLC_NONE : pesieve.t_shellc_mode
            • SHELLC_PATTERNS : pesieve.t_shellc_mode
            • diff --git a/graph_legend.png b/graph_legend.png index 9fd8831bc..02fbdac86 100644 Binary files a/graph_legend.png and b/graph_legend.png differ diff --git a/main_8cpp.html b/main_8cpp.html index 5cff955d7..94bc6bc45 100644 --- a/main_8cpp.html +++ b/main_8cpp.html @@ -210,7 +210,7 @@

              - + @@ -226,7 +226,7 @@

              - + diff --git a/main_8cpp_a0ddf1224851353fc92bfbff6f499fa97_cgraph.map b/main_8cpp_a0ddf1224851353fc92bfbff6f499fa97_cgraph.map index bca32143e..c1984e964 100644 --- a/main_8cpp_a0ddf1224851353fc92bfbff6f499fa97_cgraph.map +++ b/main_8cpp_a0ddf1224851353fc92bfbff6f499fa97_cgraph.map @@ -33,7 +33,7 @@ - + @@ -49,7 +49,7 @@ - + diff --git a/main_8cpp_a0ddf1224851353fc92bfbff6f499fa97_cgraph.png b/main_8cpp_a0ddf1224851353fc92bfbff6f499fa97_cgraph.png index 925ac02cc..2d7a509ee 100644 Binary files a/main_8cpp_a0ddf1224851353fc92bfbff6f499fa97_cgraph.png and b/main_8cpp_a0ddf1224851353fc92bfbff6f499fa97_cgraph.png differ diff --git a/namespacepesieve.html b/namespacepesieve.html index 920b0930a..5dfaa8a51 100644 --- a/namespacepesieve.html +++ b/namespacepesieve.html @@ -1714,7 +1714,7 @@

              - + @@ -2273,7 +2273,7 @@

              - + diff --git a/namespacepesieve_abbc56d07d9ca9ce478537f02e33e9c49_cgraph.map b/namespacepesieve_abbc56d07d9ca9ce478537f02e33e9c49_cgraph.map index 441d974fa..a3c8c87d5 100644 --- a/namespacepesieve_abbc56d07d9ca9ce478537f02e33e9c49_cgraph.map +++ b/namespacepesieve_abbc56d07d9ca9ce478537f02e33e9c49_cgraph.map @@ -52,7 +52,7 @@ - + diff --git a/namespacepesieve_abbc56d07d9ca9ce478537f02e33e9c49_cgraph.png b/namespacepesieve_abbc56d07d9ca9ce478537f02e33e9c49_cgraph.png index 4b76c7f53..93550e142 100644 Binary files a/namespacepesieve_abbc56d07d9ca9ce478537f02e33e9c49_cgraph.png and b/namespacepesieve_abbc56d07d9ca9ce478537f02e33e9c49_cgraph.png differ diff --git a/namespacepesieve_ad71d3d82e248bd37f2becabe0ca00f55_cgraph.map b/namespacepesieve_ad71d3d82e248bd37f2becabe0ca00f55_cgraph.map index 5f56185eb..6f3b658ad 100644 --- a/namespacepesieve_ad71d3d82e248bd37f2becabe0ca00f55_cgraph.map +++ b/namespacepesieve_ad71d3d82e248bd37f2becabe0ca00f55_cgraph.map @@ -63,7 +63,7 @@ - + diff --git a/namespacepesieve_ad71d3d82e248bd37f2becabe0ca00f55_cgraph.png b/namespacepesieve_ad71d3d82e248bd37f2becabe0ca00f55_cgraph.png index 90250b03c..4d0f3edd2 100644 Binary files a/namespacepesieve_ad71d3d82e248bd37f2becabe0ca00f55_cgraph.png and b/namespacepesieve_ad71d3d82e248bd37f2becabe0ca00f55_cgraph.png differ diff --git a/pe__sieve__api_8cpp.html b/pe__sieve__api_8cpp.html index ece2488b4..eaf8a8e54 100644 --- a/pe__sieve__api_8cpp.html +++ b/pe__sieve__api_8cpp.html @@ -298,7 +298,7 @@

              - + @@ -342,7 +342,7 @@

              - + @@ -387,7 +387,7 @@

              - + diff --git a/pe__sieve__api_8cpp_ab5ff4b4b18f55c344f1b946b9d9eb47b_cgraph.map b/pe__sieve__api_8cpp_ab5ff4b4b18f55c344f1b946b9d9eb47b_cgraph.map index fb5c55e2b..ff22d33de 100644 --- a/pe__sieve__api_8cpp_ab5ff4b4b18f55c344f1b946b9d9eb47b_cgraph.map +++ b/pe__sieve__api_8cpp_ab5ff4b4b18f55c344f1b946b9d9eb47b_cgraph.map @@ -31,7 +31,7 @@ - + @@ -75,7 +75,7 @@ - + @@ -120,6 +120,6 @@ - + diff --git a/pe__sieve__api_8cpp_ab5ff4b4b18f55c344f1b946b9d9eb47b_cgraph.png b/pe__sieve__api_8cpp_ab5ff4b4b18f55c344f1b946b9d9eb47b_cgraph.png index a057de138..a560f7389 100644 Binary files a/pe__sieve__api_8cpp_ab5ff4b4b18f55c344f1b946b9d9eb47b_cgraph.png and b/pe__sieve__api_8cpp_ab5ff4b4b18f55c344f1b946b9d9eb47b_cgraph.png differ diff --git a/scanner_8cpp_source.html b/scanner_8cpp_source.html index e493f5895..97d3f51d6 100644 --- a/scanner_8cpp_source.html +++ b/scanner_8cpp_source.html @@ -717,8 +717,8 @@
              A report from the thread scan, generated by ThreadScanner.
              - -
              virtual ThreadScanReport * scanRemote()
              + +
              virtual ThreadScanReport * scanRemote()
              A report from the working set scan, generated by WorkingSetScanner.
              diff --git a/search/all_11.js b/search/all_11.js index 211aba5ae..090d4a117 100644 --- a/search/all_11.js +++ b/search/all_11.js @@ -69,23 +69,22 @@ var searchData= ['results_5fdumper_2ecpp_66',['results_dumper.cpp',['../results__dumper_8cpp.html',1,'']]], ['results_5fdumper_2eh_67',['results_dumper.h',['../results__dumper_8h.html',1,'']]], ['resultsdumper_68',['ResultsDumper',['../classpesieve_1_1_results_dumper.html',1,'pesieve::ResultsDumper'],['../classpesieve_1_1_process_dump_report.html#a0e77b9b85b41616be4cfe0745cb94549',1,'pesieve::ProcessDumpReport::ResultsDumper'],['../classpesieve_1_1_process_scan_report.html#a0e77b9b85b41616be4cfe0745cb94549',1,'pesieve::ProcessScanReport::ResultsDumper'],['../classpesieve_1_1_results_dumper.html#a84cedbc87af0ee8b72f06fd7c6cb9b5a',1,'pesieve::ResultsDumper::ResultsDumper()']]], - ['ret_5faddr_69',['ret_addr',['../structpesieve_1_1__ctx__details.html#a4b5f5a030c362877e2772ab3493e0d6f',1,'pesieve::_ctx_details']]], - ['returned_5fhndl_70',['returned_hndl',['../structpesieve_1_1util_1_1t__refl__args.html#a2039cf10734a4e3f07e94e6068122729',1,'pesieve::util::t_refl_args']]], - ['returned_5fpid_71',['returned_pid',['../structpesieve_1_1util_1_1t__refl__args.html#a7e95cffd1d650f477bb1d64377f4f6d7',1,'pesieve::util::t_refl_args']]], - ['rip_72',['rip',['../structpesieve_1_1__ctx__details.html#a6dc0bc061045467c3d71b6644adf68b4',1,'pesieve::_ctx_details']]], - ['rsp_73',['rsp',['../structpesieve_1_1__ctx__details.html#ab19759b888e6034d29dcaf6cedeed9bd',1,'pesieve::_ctx_details']]], - ['rtl_5fclone_5fprocess_5fflags_5fcreate_5fsuspended_74',['RTL_CLONE_PROCESS_FLAGS_CREATE_SUSPENDED',['../process__reflection_8cpp.html#a32cecac9c7a7d39eb28c815e5cfae2f2',1,'process_reflection.cpp']]], - ['rtl_5fclone_5fprocess_5fflags_5finherit_5fhandles_75',['RTL_CLONE_PROCESS_FLAGS_INHERIT_HANDLES',['../process__reflection_8cpp.html#a82f1405153b8ad80df8c7398d29e19f5',1,'process_reflection.cpp']]], - ['rtl_5fclone_5fprocess_5fflags_5fno_5fsynchronize_76',['RTL_CLONE_PROCESS_FLAGS_NO_SYNCHRONIZE',['../process__reflection_8cpp.html#a9ebf762b1a1365370dcdf4d1258447d8',1,'process_reflection.cpp']]], - ['rtrim_77',['rtrim',['../namespacepesieve_1_1util.html#a31052004d33cccf72236cd5bd451fa91',1,'pesieve::util']]], - ['rule_5fcode_78',['RULE_CODE',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aa6007e2701ffdcbbf8520f4decb8bee61',1,'pesieve::RuleMatcher']]], - ['rule_5fencrypted_79',['RULE_ENCRYPTED',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aabc5eb54cc64621d0c03874dae1328fe2',1,'pesieve::RuleMatcher']]], - ['rule_5fnone_80',['RULE_NONE',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aaee38ad26682344d1747c15ac203dba27',1,'pesieve::RuleMatcher']]], - ['rule_5fobfuscated_81',['RULE_OBFUSCATED',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aaff6b2161fe8136ff7a7be0fd4cf37c31',1,'pesieve::RuleMatcher']]], - ['rule_5ftext_82',['RULE_TEXT',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aa6617b4261cc4bc38519dbfa7b5d708e7',1,'pesieve::RuleMatcher']]], - ['rulematcher_83',['RuleMatcher',['../classpesieve_1_1_rule_matcher.html',1,'pesieve::RuleMatcher'],['../classpesieve_1_1_rule_matcher.html#a977717986c584a95b87ffd73da2e8905',1,'pesieve::RuleMatcher::RuleMatcher()']]], - ['rulematchersset_84',['RuleMatchersSet',['../structpesieve_1_1_rule_matchers_set.html',1,'pesieve::RuleMatchersSet'],['../structpesieve_1_1_rule_matchers_set.html#aff5025d1a45e27e0f98cb4da745b3ff8',1,'pesieve::RuleMatchersSet::RuleMatchersSet()']]], - ['ruletype_85',['RuleType',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6a',1,'pesieve::RuleMatcher']]], - ['rva_86',['rva',['../classpesieve_1_1_pe_section.html#abb3723c684e695788cedc1654463b409',1,'pesieve::PeSection']]], - ['rvatova_87',['rvaToVa',['../classpesieve_1_1_module_data.html#a1227c638b7039f75d3bf31b61fe13bf9',1,'pesieve::ModuleData']]] + ['returned_5fhndl_69',['returned_hndl',['../structpesieve_1_1util_1_1t__refl__args.html#a2039cf10734a4e3f07e94e6068122729',1,'pesieve::util::t_refl_args']]], + ['returned_5fpid_70',['returned_pid',['../structpesieve_1_1util_1_1t__refl__args.html#a7e95cffd1d650f477bb1d64377f4f6d7',1,'pesieve::util::t_refl_args']]], + ['rip_71',['rip',['../structpesieve_1_1__ctx__details.html#a6dc0bc061045467c3d71b6644adf68b4',1,'pesieve::_ctx_details']]], + ['rsp_72',['rsp',['../structpesieve_1_1__ctx__details.html#ab19759b888e6034d29dcaf6cedeed9bd',1,'pesieve::_ctx_details']]], + ['rtl_5fclone_5fprocess_5fflags_5fcreate_5fsuspended_73',['RTL_CLONE_PROCESS_FLAGS_CREATE_SUSPENDED',['../process__reflection_8cpp.html#a32cecac9c7a7d39eb28c815e5cfae2f2',1,'process_reflection.cpp']]], + ['rtl_5fclone_5fprocess_5fflags_5finherit_5fhandles_74',['RTL_CLONE_PROCESS_FLAGS_INHERIT_HANDLES',['../process__reflection_8cpp.html#a82f1405153b8ad80df8c7398d29e19f5',1,'process_reflection.cpp']]], + ['rtl_5fclone_5fprocess_5fflags_5fno_5fsynchronize_75',['RTL_CLONE_PROCESS_FLAGS_NO_SYNCHRONIZE',['../process__reflection_8cpp.html#a9ebf762b1a1365370dcdf4d1258447d8',1,'process_reflection.cpp']]], + ['rtrim_76',['rtrim',['../namespacepesieve_1_1util.html#a31052004d33cccf72236cd5bd451fa91',1,'pesieve::util']]], + ['rule_5fcode_77',['RULE_CODE',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aa6007e2701ffdcbbf8520f4decb8bee61',1,'pesieve::RuleMatcher']]], + ['rule_5fencrypted_78',['RULE_ENCRYPTED',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aabc5eb54cc64621d0c03874dae1328fe2',1,'pesieve::RuleMatcher']]], + ['rule_5fnone_79',['RULE_NONE',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aaee38ad26682344d1747c15ac203dba27',1,'pesieve::RuleMatcher']]], + ['rule_5fobfuscated_80',['RULE_OBFUSCATED',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aaff6b2161fe8136ff7a7be0fd4cf37c31',1,'pesieve::RuleMatcher']]], + ['rule_5ftext_81',['RULE_TEXT',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6aa6617b4261cc4bc38519dbfa7b5d708e7',1,'pesieve::RuleMatcher']]], + ['rulematcher_82',['RuleMatcher',['../classpesieve_1_1_rule_matcher.html',1,'pesieve::RuleMatcher'],['../classpesieve_1_1_rule_matcher.html#a977717986c584a95b87ffd73da2e8905',1,'pesieve::RuleMatcher::RuleMatcher()']]], + ['rulematchersset_83',['RuleMatchersSet',['../structpesieve_1_1_rule_matchers_set.html',1,'pesieve::RuleMatchersSet'],['../structpesieve_1_1_rule_matchers_set.html#aff5025d1a45e27e0f98cb4da745b3ff8',1,'pesieve::RuleMatchersSet::RuleMatchersSet()']]], + ['ruletype_84',['RuleType',['../classpesieve_1_1_rule_matcher.html#a4673a0acf40a39a008489e1d74bc0c6a',1,'pesieve::RuleMatcher']]], + ['rva_85',['rva',['../classpesieve_1_1_pe_section.html#abb3723c684e695788cedc1654463b409',1,'pesieve::PeSection']]], + ['rvatova_86',['rvaToVa',['../classpesieve_1_1_module_data.html#a1227c638b7039f75d3bf31b61fe13bf9',1,'pesieve::ModuleData']]] ]; diff --git a/search/all_12.js b/search/all_12.js index a37e85441..5b616b637 100644 --- a/search/all_12.js +++ b/search/all_12.js @@ -56,57 +56,58 @@ var searchData= ['setsuspicious_53',['setSuspicious',['../classpesieve_1_1_scanned_module.html#a1550cf5ee7a95ec2c1c17dc8627ad0bf',1,'pesieve::ScannedModule']]], ['settableinpe_54',['setTableInPe',['../classpesieve_1_1_import_table_buffer.html#abf53ddda82d5e91d4b9e1cf02b8043d6',1,'pesieve::ImportTableBuffer']]], ['settings_55',['settings',['../structpesieve_1_1_chunk_stats.html#a1268301237205e183a7fd2d097c70397',1,'pesieve::ChunkStats']]], - ['shellc_5fcount_56',['SHELLC_COUNT',['../classpesieve_1_1t__shellc__mode.html#abb24e6cbf35bbad15709d7b7c4d21c71',1,'pesieve.t_shellc_mode.SHELLC_COUNT'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49acb31dc14f5b66f4be2d4593cb10d3385',1,'SHELLC_COUNT: pe_sieve_types.h']]], - ['shellc_5fmode_5fmode_5fto_5fid_57',['shellc_mode_mode_to_id',['../namespacepesieve.html#a175ef72c9fd6303f190d564e65d9614a',1,'pesieve']]], - ['shellc_5fnone_58',['SHELLC_NONE',['../classpesieve_1_1t__shellc__mode.html#a7d4e9c7bdc63e28079f0a663287371aa',1,'pesieve.t_shellc_mode.SHELLC_NONE'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49a806397db03996a9ad3582b4a5249a6b5',1,'SHELLC_NONE: pe_sieve_types.h']]], - ['shellc_5fpatterns_59',['SHELLC_PATTERNS',['../classpesieve_1_1t__shellc__mode.html#a4371c512776afe9e6faeac818be15c14',1,'pesieve.t_shellc_mode.SHELLC_PATTERNS'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49af374abe8ac723478824a06eb79fd3edb',1,'SHELLC_PATTERNS: pe_sieve_types.h']]], - ['shellc_5fpatterns_5fand_5fstats_60',['SHELLC_PATTERNS_AND_STATS',['../classpesieve_1_1t__shellc__mode.html#a16c88cc8e50ca3b6a8e08942d93475f1',1,'pesieve.t_shellc_mode.SHELLC_PATTERNS_AND_STATS'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49ae9f1a1eb467fe09be5745826fcc96987',1,'SHELLC_PATTERNS_AND_STATS: pe_sieve_types.h']]], - ['shellc_5fpatterns_5for_5fstats_61',['SHELLC_PATTERNS_OR_STATS',['../classpesieve_1_1t__shellc__mode.html#a7ed46ef5720148741ee3d9d1f416694a',1,'pesieve.t_shellc_mode.SHELLC_PATTERNS_OR_STATS'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49ab0768291981a452e0e33c42a740b97ee',1,'SHELLC_PATTERNS_OR_STATS: pe_sieve_types.h']]], - ['shellc_5fstats_62',['SHELLC_STATS',['../classpesieve_1_1t__shellc__mode.html#a67ddfa30a058f878421d277af59fbf2e',1,'pesieve.t_shellc_mode.SHELLC_STATS'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49a49155121e3f2b030dde86a3d8ed80760',1,'SHELLC_STATS: pe_sieve_types.h']]], - ['shellcode_63',['shellcode',['../structparams.html#a5063529cd6e6950334929d22164d3868',1,'params::shellcode'],['../namespacedemo.html#a6cdb502544cf88590852419885d95c92',1,'demo.shellcode']]], - ['shift_5fartefacts_64',['shift_artefacts',['../namespacepesieve.html#ab28bfe1ca7dd95f63741ac0089f5343a',1,'pesieve']]], - ['shiftpeheader_65',['shiftPeHeader',['../classpesieve_1_1_pe_reconstructor.html#a071ac1f5f01c749bb92fd4ac93c13774',1,'pesieve::PeReconstructor']]], - ['should_5fscan_5fcontext_66',['should_scan_context',['../thread__scanner_8cpp.html#acde231c42b9527dcc026402dcb8b9d87',1,'thread_scanner.cpp']]], - ['shouldacceptexport_67',['shouldAcceptExport',['../classpesieve_1_1_thunk_found_callback.html#ab4301142df4586549b52c8ede3666eea',1,'pesieve::ThunkFoundCallback']]], - ['shouldprocessva_68',['shouldProcessVA',['../classpesieve_1_1_thunk_found_callback.html#a471618623bcca031182bed49c36db30e',1,'pesieve::ThunkFoundCallback']]], - ['size_69',['size',['../structpesieve_1_1_chunk_stats.html#a1a99134b17150d91a46a5a3a669063bc',1,'pesieve::ChunkStats::size'],['../structpesieve_1_1__t__pattern.html#a5f8a13e6e7fa8367d83bb9306ccca9d8',1,'pesieve::_t_pattern::size'],['../structpesieve_1_1util_1_1__mem__region__info.html#a5b8ade2cf0b8931e4f81b98ae2bfdac5',1,'pesieve::util::_mem_region_info::size'],['../classpesieve_1_1_patch_list.html#ab6fc10f0853f55604093c1b1d29d60df',1,'pesieve::PatchList::size()']]], - ['sizeofdllsspace_70',['sizeOfDllsSpace',['../classpesieve_1_1_i_a_t_block.html#ad2ec1f1e2e0c6934a497f6f4de19ed8e',1,'pesieve::IATBlock']]], - ['sizeofnamesspace_71',['sizeOfNamesSpace',['../classpesieve_1_1_i_a_t_thunks_series.html#ac6382d6ee5d6eae79c47e9ff6af8806b',1,'pesieve::IATThunksSeries']]], - ['skipped_72',['skipped',['../structreport.html#aa49ebcf3170fe05413a02a2af0ef5d9b',1,'report']]], - ['skippedmodulereport_73',['SkippedModuleReport',['../classpesieve_1_1_skipped_module_report.html',1,'pesieve::SkippedModuleReport'],['../classpesieve_1_1_skipped_module_report.html#a9fde7e6d86205f7d71394ad5f533df68',1,'pesieve::SkippedModuleReport::SkippedModuleReport()']]], - ['snapshothandle_74',['SnapshotHandle',['../namespacepesieve_1_1util.html#a6af9e73116d4d74647d319a492b721b0',1,'pesieve::util']]], - ['splitseries_75',['splitSeries',['../classpesieve_1_1_i_a_t_block.html#af25037eb1bb7ea83fa7e5a24807727d7',1,'pesieve::IATBlock']]], - ['stack_5fframe_76',['stack_frame',['../struct__t__stack__enum__params.html#afd374d69c557b225099cff673e6ab6d7',1,'_t_stack_enum_params']]], - ['stackframescount_77',['stackFramesCount',['../structpesieve_1_1__ctx__details.html#aabca56adbcd0155923d8e6b0e62599c5',1,'pesieve::_ctx_details']]], - ['start_78',['start',['../classpesieve_1_1_scanned_module.html#a1257d00fc075f58c68a2f2f3ee2580c3',1,'pesieve::ScannedModule']]], - ['start_5faddr_79',['start_addr',['../structpesieve_1_1util_1_1__thread__info.html#a2d408cca43d2e48530d63c394755e96b',1,'pesieve::util::_thread_info']]], - ['start_5fva_80',['start_va',['../classpesieve_1_1_mem_page_data.html#aa47136298a2aecc8cc011162cf7a0571',1,'pesieve::MemPageData']]], - ['startcontext_81',['StartContext',['../namespacepesieve_1_1util.html#a867430ba8efef3a8f89e826a34791db1',1,'pesieve::util']]], - ['startoffset_82',['startOffset',['../classpesieve_1_1_i_a_t_thunks_series.html#a2c8fb26493bbda8f2c53d4b28c19531a',1,'pesieve::IATThunksSeries']]], - ['startroutine_83',['StartRoutine',['../namespacepesieve_1_1util.html#a243a5bb6446feaa7c25fa56debfc0384',1,'pesieve::util']]], - ['startrva_84',['startRva',['../classpesieve_1_1_patch_list_1_1_patch.html#a7b946d650da353c56690ff150eb4a82c',1,'pesieve::PatchList::Patch']]], - ['state_85',['state',['../structpesieve_1_1util_1_1__thread__info__ext.html#a64f10518106ade775aecd7f5c2caaf65',1,'pesieve::util::_thread_info_ext']]], - ['stats_86',['stats',['../classpesieve_1_1_thread_scan_report.html#a00f0b36826c124dc6be154f0cdeb7f83',1,'pesieve::ThreadScanReport::stats'],['../classpesieve_1_1_working_set_scan_report.html#a2b63bfed29add17e9db10f21936cedc0',1,'pesieve::WorkingSetScanReport::stats']]], - ['stats_2eh_87',['stats.h',['../stats_8h.html',1,'']]], - ['stats_5fanalyzer_2ecpp_88',['stats_analyzer.cpp',['../stats__analyzer_8cpp.html',1,'']]], - ['stats_5fanalyzer_2eh_89',['stats_analyzer.h',['../stats__analyzer_8h.html',1,'']]], - ['stats_5futil_2eh_90',['stats_util.h',['../stats__util_8h.html',1,'']]], - ['statssettings_91',['StatsSettings',['../structpesieve_1_1_stats_settings.html',1,'pesieve::StatsSettings'],['../structpesieve_1_1_stats_settings.html#a6cc87183e4f04394819667bd2acc00ac',1,'pesieve::StatsSettings::StatsSettings()']]], - ['status_92',['status',['../classpesieve_1_1_module_scan_report.html#a10b0bdf16cb9e7af32e1ab9b35532f68',1,'pesieve::ModuleScanReport']]], - ['std_5fdev_5fcalc_2eh_93',['std_dev_calc.h',['../std__dev__calc_8h.html',1,'']]], - ['stddeviationcalc_94',['StdDeviationCalc',['../classpesieve_1_1stats_1_1_std_deviation_calc.html',1,'pesieve::stats::StdDeviationCalc'],['../classpesieve_1_1stats_1_1_std_deviation_calc.html#a4ec518e853777eb643d82926f0ad6c70',1,'pesieve::stats::StdDeviationCalc::StdDeviationCalc()']]], - ['stop_5fva_95',['stop_va',['../classpesieve_1_1_mem_page_data.html#a7c151bd819b2444eb7e93c92fcd4f8ce',1,'pesieve::MemPageData']]], - ['storedfunc_96',['storedFunc',['../classpesieve_1_1_i_a_t_scan_report.html#a7a631d5a508e52d214764f5d25490b2e',1,'pesieve::IATScanReport']]], - ['string_5fto_5flist_97',['string_to_list',['../namespacepesieve_1_1util.html#a6bf8eed39c860ca4caf8dc081b57529e',1,'pesieve::util']]], - ['strings_5futil_2ecpp_98',['strings_util.cpp',['../strings__util_8cpp.html',1,'']]], - ['strings_5futil_2eh_99',['strings_util.h',['../strings__util_8h.html',1,'']]], - ['stringscount_100',['stringsCount',['../structpesieve_1_1_chunk_stats.html#a41e1a3748f347a69f1db454cb3dd2651',1,'pesieve::ChunkStats']]], - ['strip_5fprefix_101',['strip_prefix',['../namespacepesieve_1_1util.html#a2d19e21063f990f24ceea5c64d452cfc',1,'pesieve::util']]], - ['summarize_102',['summarize',['../classpesieve_1_1_area_entropy_stats.html#a55525d7498ddf04738ce1fac9332be3f',1,'pesieve::AreaEntropyStats::summarize()'],['../structpesieve_1_1_chunk_stats.html#ac68e19c8316bf003c2fbdea739176001',1,'pesieve::ChunkStats::summarize()'],['../classpesieve_1_1_area_multi_stats.html#adc0566558c7de4604692be9fec9ba0e3',1,'pesieve::AreaMultiStats::summarize()'],['../classpesieve_1_1_area_stats.html#a5b449d535857a37328518f752ab2f610',1,'pesieve::AreaStats::summarize()']]], - ['susp_5faddr_103',['susp_addr',['../classpesieve_1_1_thread_scan_report.html#a5a930aaa32e9de46d95b25018a373cbc',1,'pesieve::ThreadScanReport']]], - ['suspicious_104',['suspicious',['../structreport.html#a5ee5e4dbcf6777455b2b32b1529d4980',1,'report']]], - ['switchtowow64path_105',['switchToWow64Path',['../classpesieve_1_1_module_data.html#a2e919f44d71aad97bb40a77086c28e7b',1,'pesieve::ModuleData']]], - ['symbols_106',['symbols',['../classpesieve_1_1_process_scanner.html#ac9a6ee9cd3632a5ccd3f03742700959f',1,'pesieve::ProcessScanner::symbols'],['../classpesieve_1_1_thread_scanner.html#ad455f81b20ec49dc2968d6f2db67ae13',1,'pesieve::ThreadScanner::symbols']]], - ['sys_5fstart_5faddr_107',['sys_start_addr',['../structpesieve_1_1util_1_1__thread__info__ext.html#a015d9ec862bebffabeeea74cc94c6c03',1,'pesieve::util::_thread_info_ext']]], - ['szmodname_108',['szModName',['../classpesieve_1_1_module_data.html#ab7463bd2db1ce6343e1be66600c48cd8',1,'pesieve::ModuleData']]] + ['shccandidates_56',['shcCandidates',['../structpesieve_1_1__ctx__details.html#a44ca7a32918f0eab5a8d9cf14080e0c0',1,'pesieve::_ctx_details']]], + ['shellc_5fcount_57',['SHELLC_COUNT',['../classpesieve_1_1t__shellc__mode.html#abb24e6cbf35bbad15709d7b7c4d21c71',1,'pesieve.t_shellc_mode.SHELLC_COUNT'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49acb31dc14f5b66f4be2d4593cb10d3385',1,'SHELLC_COUNT: pe_sieve_types.h']]], + ['shellc_5fmode_5fmode_5fto_5fid_58',['shellc_mode_mode_to_id',['../namespacepesieve.html#a175ef72c9fd6303f190d564e65d9614a',1,'pesieve']]], + ['shellc_5fnone_59',['SHELLC_NONE',['../classpesieve_1_1t__shellc__mode.html#a7d4e9c7bdc63e28079f0a663287371aa',1,'pesieve.t_shellc_mode.SHELLC_NONE'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49a806397db03996a9ad3582b4a5249a6b5',1,'SHELLC_NONE: pe_sieve_types.h']]], + ['shellc_5fpatterns_60',['SHELLC_PATTERNS',['../classpesieve_1_1t__shellc__mode.html#a4371c512776afe9e6faeac818be15c14',1,'pesieve.t_shellc_mode.SHELLC_PATTERNS'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49af374abe8ac723478824a06eb79fd3edb',1,'SHELLC_PATTERNS: pe_sieve_types.h']]], + ['shellc_5fpatterns_5fand_5fstats_61',['SHELLC_PATTERNS_AND_STATS',['../classpesieve_1_1t__shellc__mode.html#a16c88cc8e50ca3b6a8e08942d93475f1',1,'pesieve.t_shellc_mode.SHELLC_PATTERNS_AND_STATS'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49ae9f1a1eb467fe09be5745826fcc96987',1,'SHELLC_PATTERNS_AND_STATS: pe_sieve_types.h']]], + ['shellc_5fpatterns_5for_5fstats_62',['SHELLC_PATTERNS_OR_STATS',['../classpesieve_1_1t__shellc__mode.html#a7ed46ef5720148741ee3d9d1f416694a',1,'pesieve.t_shellc_mode.SHELLC_PATTERNS_OR_STATS'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49ab0768291981a452e0e33c42a740b97ee',1,'SHELLC_PATTERNS_OR_STATS: pe_sieve_types.h']]], + ['shellc_5fstats_63',['SHELLC_STATS',['../classpesieve_1_1t__shellc__mode.html#a67ddfa30a058f878421d277af59fbf2e',1,'pesieve.t_shellc_mode.SHELLC_STATS'],['../pe__sieve__types_8h.html#a440fabe616455608f0c66f6e10116e49a49155121e3f2b030dde86a3d8ed80760',1,'SHELLC_STATS: pe_sieve_types.h']]], + ['shellcode_64',['shellcode',['../structparams.html#a5063529cd6e6950334929d22164d3868',1,'params::shellcode'],['../namespacedemo.html#a6cdb502544cf88590852419885d95c92',1,'demo.shellcode']]], + ['shift_5fartefacts_65',['shift_artefacts',['../namespacepesieve.html#ab28bfe1ca7dd95f63741ac0089f5343a',1,'pesieve']]], + ['shiftpeheader_66',['shiftPeHeader',['../classpesieve_1_1_pe_reconstructor.html#a071ac1f5f01c749bb92fd4ac93c13774',1,'pesieve::PeReconstructor']]], + ['should_5fscan_5fcontext_67',['should_scan_context',['../thread__scanner_8cpp.html#acde231c42b9527dcc026402dcb8b9d87',1,'thread_scanner.cpp']]], + ['shouldacceptexport_68',['shouldAcceptExport',['../classpesieve_1_1_thunk_found_callback.html#ab4301142df4586549b52c8ede3666eea',1,'pesieve::ThunkFoundCallback']]], + ['shouldprocessva_69',['shouldProcessVA',['../classpesieve_1_1_thunk_found_callback.html#a471618623bcca031182bed49c36db30e',1,'pesieve::ThunkFoundCallback']]], + ['size_70',['size',['../structpesieve_1_1_chunk_stats.html#a1a99134b17150d91a46a5a3a669063bc',1,'pesieve::ChunkStats::size'],['../structpesieve_1_1__t__pattern.html#a5f8a13e6e7fa8367d83bb9306ccca9d8',1,'pesieve::_t_pattern::size'],['../structpesieve_1_1util_1_1__mem__region__info.html#a5b8ade2cf0b8931e4f81b98ae2bfdac5',1,'pesieve::util::_mem_region_info::size'],['../classpesieve_1_1_patch_list.html#ab6fc10f0853f55604093c1b1d29d60df',1,'pesieve::PatchList::size()']]], + ['sizeofdllsspace_71',['sizeOfDllsSpace',['../classpesieve_1_1_i_a_t_block.html#ad2ec1f1e2e0c6934a497f6f4de19ed8e',1,'pesieve::IATBlock']]], + ['sizeofnamesspace_72',['sizeOfNamesSpace',['../classpesieve_1_1_i_a_t_thunks_series.html#ac6382d6ee5d6eae79c47e9ff6af8806b',1,'pesieve::IATThunksSeries']]], + ['skipped_73',['skipped',['../structreport.html#aa49ebcf3170fe05413a02a2af0ef5d9b',1,'report']]], + ['skippedmodulereport_74',['SkippedModuleReport',['../classpesieve_1_1_skipped_module_report.html',1,'pesieve::SkippedModuleReport'],['../classpesieve_1_1_skipped_module_report.html#a9fde7e6d86205f7d71394ad5f533df68',1,'pesieve::SkippedModuleReport::SkippedModuleReport()']]], + ['snapshothandle_75',['SnapshotHandle',['../namespacepesieve_1_1util.html#a6af9e73116d4d74647d319a492b721b0',1,'pesieve::util']]], + ['splitseries_76',['splitSeries',['../classpesieve_1_1_i_a_t_block.html#af25037eb1bb7ea83fa7e5a24807727d7',1,'pesieve::IATBlock']]], + ['stack_5fframe_77',['stack_frame',['../struct__t__stack__enum__params.html#afd374d69c557b225099cff673e6ab6d7',1,'_t_stack_enum_params']]], + ['stackframescount_78',['stackFramesCount',['../structpesieve_1_1__ctx__details.html#aabca56adbcd0155923d8e6b0e62599c5',1,'pesieve::_ctx_details']]], + ['start_79',['start',['../classpesieve_1_1_scanned_module.html#a1257d00fc075f58c68a2f2f3ee2580c3',1,'pesieve::ScannedModule']]], + ['start_5faddr_80',['start_addr',['../structpesieve_1_1util_1_1__thread__info.html#a2d408cca43d2e48530d63c394755e96b',1,'pesieve::util::_thread_info']]], + ['start_5fva_81',['start_va',['../classpesieve_1_1_mem_page_data.html#aa47136298a2aecc8cc011162cf7a0571',1,'pesieve::MemPageData']]], + ['startcontext_82',['StartContext',['../namespacepesieve_1_1util.html#a867430ba8efef3a8f89e826a34791db1',1,'pesieve::util']]], + ['startoffset_83',['startOffset',['../classpesieve_1_1_i_a_t_thunks_series.html#a2c8fb26493bbda8f2c53d4b28c19531a',1,'pesieve::IATThunksSeries']]], + ['startroutine_84',['StartRoutine',['../namespacepesieve_1_1util.html#a243a5bb6446feaa7c25fa56debfc0384',1,'pesieve::util']]], + ['startrva_85',['startRva',['../classpesieve_1_1_patch_list_1_1_patch.html#a7b946d650da353c56690ff150eb4a82c',1,'pesieve::PatchList::Patch']]], + ['state_86',['state',['../structpesieve_1_1util_1_1__thread__info__ext.html#a64f10518106ade775aecd7f5c2caaf65',1,'pesieve::util::_thread_info_ext']]], + ['stats_87',['stats',['../classpesieve_1_1_thread_scan_report.html#a00f0b36826c124dc6be154f0cdeb7f83',1,'pesieve::ThreadScanReport::stats'],['../classpesieve_1_1_working_set_scan_report.html#a2b63bfed29add17e9db10f21936cedc0',1,'pesieve::WorkingSetScanReport::stats']]], + ['stats_2eh_88',['stats.h',['../stats_8h.html',1,'']]], + ['stats_5fanalyzer_2ecpp_89',['stats_analyzer.cpp',['../stats__analyzer_8cpp.html',1,'']]], + ['stats_5fanalyzer_2eh_90',['stats_analyzer.h',['../stats__analyzer_8h.html',1,'']]], + ['stats_5futil_2eh_91',['stats_util.h',['../stats__util_8h.html',1,'']]], + ['statssettings_92',['StatsSettings',['../structpesieve_1_1_stats_settings.html',1,'pesieve::StatsSettings'],['../structpesieve_1_1_stats_settings.html#a6cc87183e4f04394819667bd2acc00ac',1,'pesieve::StatsSettings::StatsSettings()']]], + ['status_93',['status',['../classpesieve_1_1_module_scan_report.html#a10b0bdf16cb9e7af32e1ab9b35532f68',1,'pesieve::ModuleScanReport']]], + ['std_5fdev_5fcalc_2eh_94',['std_dev_calc.h',['../std__dev__calc_8h.html',1,'']]], + ['stddeviationcalc_95',['StdDeviationCalc',['../classpesieve_1_1stats_1_1_std_deviation_calc.html',1,'pesieve::stats::StdDeviationCalc'],['../classpesieve_1_1stats_1_1_std_deviation_calc.html#a4ec518e853777eb643d82926f0ad6c70',1,'pesieve::stats::StdDeviationCalc::StdDeviationCalc()']]], + ['stop_5fva_96',['stop_va',['../classpesieve_1_1_mem_page_data.html#a7c151bd819b2444eb7e93c92fcd4f8ce',1,'pesieve::MemPageData']]], + ['storedfunc_97',['storedFunc',['../classpesieve_1_1_i_a_t_scan_report.html#a7a631d5a508e52d214764f5d25490b2e',1,'pesieve::IATScanReport']]], + ['string_5fto_5flist_98',['string_to_list',['../namespacepesieve_1_1util.html#a6bf8eed39c860ca4caf8dc081b57529e',1,'pesieve::util']]], + ['strings_5futil_2ecpp_99',['strings_util.cpp',['../strings__util_8cpp.html',1,'']]], + ['strings_5futil_2eh_100',['strings_util.h',['../strings__util_8h.html',1,'']]], + ['stringscount_101',['stringsCount',['../structpesieve_1_1_chunk_stats.html#a41e1a3748f347a69f1db454cb3dd2651',1,'pesieve::ChunkStats']]], + ['strip_5fprefix_102',['strip_prefix',['../namespacepesieve_1_1util.html#a2d19e21063f990f24ceea5c64d452cfc',1,'pesieve::util']]], + ['summarize_103',['summarize',['../classpesieve_1_1_area_entropy_stats.html#a55525d7498ddf04738ce1fac9332be3f',1,'pesieve::AreaEntropyStats::summarize()'],['../structpesieve_1_1_chunk_stats.html#ac68e19c8316bf003c2fbdea739176001',1,'pesieve::ChunkStats::summarize()'],['../classpesieve_1_1_area_multi_stats.html#adc0566558c7de4604692be9fec9ba0e3',1,'pesieve::AreaMultiStats::summarize()'],['../classpesieve_1_1_area_stats.html#a5b449d535857a37328518f752ab2f610',1,'pesieve::AreaStats::summarize()']]], + ['susp_5faddr_104',['susp_addr',['../classpesieve_1_1_thread_scan_report.html#a5a930aaa32e9de46d95b25018a373cbc',1,'pesieve::ThreadScanReport']]], + ['suspicious_105',['suspicious',['../structreport.html#a5ee5e4dbcf6777455b2b32b1529d4980',1,'report']]], + ['switchtowow64path_106',['switchToWow64Path',['../classpesieve_1_1_module_data.html#a2e919f44d71aad97bb40a77086c28e7b',1,'pesieve::ModuleData']]], + ['symbols_107',['symbols',['../classpesieve_1_1_process_scanner.html#ac9a6ee9cd3632a5ccd3f03742700959f',1,'pesieve::ProcessScanner::symbols'],['../classpesieve_1_1_thread_scanner.html#ad455f81b20ec49dc2968d6f2db67ae13',1,'pesieve::ThreadScanner::symbols']]], + ['sys_5fstart_5faddr_108',['sys_start_addr',['../structpesieve_1_1util_1_1__thread__info__ext.html#a015d9ec862bebffabeeea74cc94c6c03',1,'pesieve::util::_thread_info_ext']]], + ['szmodname_109',['szModName',['../classpesieve_1_1_module_data.html#ab7463bd2db1ce6343e1be66600c48cd8',1,'pesieve::ModuleData']]] ]; diff --git a/search/all_b.js b/search/all_b.js index 22a7a3c31..6c092bcdd 100644 --- a/search/all_b.js +++ b/search/all_b.js @@ -1,33 +1,34 @@ var searchData= [ - ['laststr_0',['lastStr',['../structpesieve_1_1_chunk_stats.html#aa3dd6619cda8fd6d7e6a0471a2ab9c26',1,'pesieve::ChunkStats']]], - ['lastusage_1',['lastUsage',['../structpesieve_1_1_cached_module.html#ac346042e22490dec922835547a992e05',1,'pesieve::CachedModule']]], - ['length_2',['length',['../struct___p_a_r_a_m___s_t_r_i_n_g.html#a7996767bb0f2ac6ccfc42d6ddb210bcf',1,'_PARAM_STRING::length'],['../namespacedemo.html#abc3711f6440e69ac690f99e61099b9d2',1,'demo.length']]], - ['lib_3',['lib',['../namespacepesieve.html#aca0538d4001454cd1ec5d9c2df390ac8',1,'pesieve']]], - ['lib_5fname_4',['LIB_NAME',['../pe__sieve__api_8cpp.html#a6e43beaa714b1bf01ce2271440786e38',1,'pe_sieve_api.cpp']]], - ['list_5fdumped_5fmodules_5',['list_dumped_modules',['../classpesieve_1_1_process_dump_report.html#a849cea7d3ce9eb54d1e405f35ded482c',1,'pesieve::ProcessDumpReport']]], - ['listmodules_6',['listModules',['../classpesieve_1_1_process_scan_report.html#afea529d36f778ea890c8c347cec57c9f',1,'pesieve::ProcessScanReport']]], - ['load_7',['load',['../classpesieve_1_1_mem_page_data.html#a01d3a9dc59b2965fa6defbc4dfda8524',1,'pesieve::MemPageData']]], - ['load_5fminidumpwritedump_8',['load_MiniDumpWriteDump',['../namespacepesieve_1_1util.html#a457aa5b713197197b574a0ab8c64555b',1,'pesieve::util']]], - ['load_5fpsscapturefreesnapshot_9',['load_PssCaptureFreeSnapshot',['../namespacepesieve_1_1util.html#aefec5a38617d857c79158986bf31e35d',1,'pesieve::util']]], - ['load_5frtlcreateprocessreflection_10',['load_RtlCreateProcessReflection',['../namespacepesieve_1_1util.html#aaa37231fc8a56358e0bc48341ac002f5',1,'pesieve::util']]], - ['loadcached_11',['loadCached',['../classpesieve_1_1_modules_cache.html#a9d5758c091cc26b610b52ce5b6db5207',1,'pesieve::ModulesCache']]], - ['loadeddata_12',['loadedData',['../classpesieve_1_1_mem_page_data.html#a1a846ed452227d685a50a72ea516d0f9',1,'pesieve::MemPageData']]], - ['loadedsection_13',['loadedSection',['../classpesieve_1_1_pe_section.html#a81b7086cb5282d2a4fbd7f31353d144e',1,'pesieve::PeSection']]], - ['loadedsize_14',['loadedSize',['../classpesieve_1_1_pe_section.html#a45e6b2d32b562e2feb8cd5bb33ac6eb2',1,'pesieve::PeSection']]], - ['loadfullimage_15',['loadFullImage',['../classpesieve_1_1_remote_module_data.html#aae5bff1125a636a7faf7052ae32169e4',1,'pesieve::RemoteModuleData']]], - ['loadheader_16',['loadHeader',['../classpesieve_1_1_remote_module_data.html#a457911397fddaf4d660cf8330a00bb20',1,'pesieve::RemoteModuleData']]], - ['loadimportslist_17',['loadImportsList',['../classpesieve_1_1_module_data.html#acad74839a2978c3465c09bb93a3a2dc5',1,'pesieve::ModuleData::loadImportsList()'],['../classpesieve_1_1_remote_module_data.html#a4a7d767d81581e48f429f57286462406',1,'pesieve::RemoteModuleData::loadImportsList()']]], - ['loadimportthunks_18',['loadImportThunks',['../classpesieve_1_1_module_data.html#af0313c259e26056468c62b7b0aee5399',1,'pesieve::ModuleData']]], - ['loadmappedname_19',['loadMappedName',['../classpesieve_1_1_mem_page_data.html#a0b0278c8ee2cd31e5d36cec1a08edeef',1,'pesieve::MemPageData']]], - ['loadmodulename_20',['loadModuleName',['../classpesieve_1_1_mem_page_data.html#a683ee088e6b736f33491d54243a5b6a4',1,'pesieve::MemPageData::loadModuleName()'],['../classpesieve_1_1_module_data.html#afe5c22949731e3387a32ce58d241df1c',1,'pesieve::ModuleData::loadModuleName()']]], - ['loadoriginal_21',['loadOriginal',['../classpesieve_1_1_module_data.html#a729adaeb197b9f1415ff35e98e24c203',1,'pesieve::ModuleData::loadOriginal()'],['../classpesieve_1_1_pe_section.html#ae0525b58e8fd1eb8426d5eb2ebe1d278',1,'pesieve::PeSection::loadOriginal()']]], - ['loadpatternfile_22',['loadPatternFile',['../classpesieve_1_1_pattern_matcher.html#a3eea8c3106af7207969fab70f2176844',1,'pesieve::PatternMatcher']]], - ['loadrelocatedfields_23',['loadRelocatedFields',['../classpesieve_1_1_module_data.html#a561bfce148fdcf705144537fa2739bc2',1,'pesieve::ModuleData']]], - ['loadremote_24',['loadRemote',['../classpesieve_1_1_pe_section.html#a2431e70802f32bfec22c3bf23a7a79d2',1,'pesieve::PeSection']]], - ['lock_25',['Lock',['../structpesieve_1_1util_1_1_mutex.html#a1d253302cb2cda6c5ea0b76192cd9e2f',1,'pesieve::util::Mutex']]], - ['long_5fpath_5fprefix_26',['LONG_PATH_PREFIX',['../path__converter_8cpp.html#a10ada049714deddcb7c882a173f62999',1,'path_converter.cpp']]], - ['longeststr_27',['longestStr',['../structpesieve_1_1_chunk_stats.html#a5a4a7722c336a239ceed6a087740936c',1,'pesieve::ChunkStats']]], - ['lpcontext_28',['lpContext',['../namespacepesieve_1_1util.html#a474e517f22ad667eca359f745537886b',1,'pesieve::util']]], - ['ltrim_29',['ltrim',['../namespacepesieve_1_1util.html#a0436803ad7df590457409147fa98fb1e',1,'pesieve::util']]] + ['last_5fret_0',['last_ret',['../structpesieve_1_1__ctx__details.html#a98c61b583bcc9251354d2e199b1c5523',1,'pesieve::_ctx_details']]], + ['laststr_1',['lastStr',['../structpesieve_1_1_chunk_stats.html#aa3dd6619cda8fd6d7e6a0471a2ab9c26',1,'pesieve::ChunkStats']]], + ['lastusage_2',['lastUsage',['../structpesieve_1_1_cached_module.html#ac346042e22490dec922835547a992e05',1,'pesieve::CachedModule']]], + ['length_3',['length',['../struct___p_a_r_a_m___s_t_r_i_n_g.html#a7996767bb0f2ac6ccfc42d6ddb210bcf',1,'_PARAM_STRING::length'],['../namespacedemo.html#abc3711f6440e69ac690f99e61099b9d2',1,'demo.length']]], + ['lib_4',['lib',['../namespacepesieve.html#aca0538d4001454cd1ec5d9c2df390ac8',1,'pesieve']]], + ['lib_5fname_5',['LIB_NAME',['../pe__sieve__api_8cpp.html#a6e43beaa714b1bf01ce2271440786e38',1,'pe_sieve_api.cpp']]], + ['list_5fdumped_5fmodules_6',['list_dumped_modules',['../classpesieve_1_1_process_dump_report.html#a849cea7d3ce9eb54d1e405f35ded482c',1,'pesieve::ProcessDumpReport']]], + ['listmodules_7',['listModules',['../classpesieve_1_1_process_scan_report.html#afea529d36f778ea890c8c347cec57c9f',1,'pesieve::ProcessScanReport']]], + ['load_8',['load',['../classpesieve_1_1_mem_page_data.html#a01d3a9dc59b2965fa6defbc4dfda8524',1,'pesieve::MemPageData']]], + ['load_5fminidumpwritedump_9',['load_MiniDumpWriteDump',['../namespacepesieve_1_1util.html#a457aa5b713197197b574a0ab8c64555b',1,'pesieve::util']]], + ['load_5fpsscapturefreesnapshot_10',['load_PssCaptureFreeSnapshot',['../namespacepesieve_1_1util.html#aefec5a38617d857c79158986bf31e35d',1,'pesieve::util']]], + ['load_5frtlcreateprocessreflection_11',['load_RtlCreateProcessReflection',['../namespacepesieve_1_1util.html#aaa37231fc8a56358e0bc48341ac002f5',1,'pesieve::util']]], + ['loadcached_12',['loadCached',['../classpesieve_1_1_modules_cache.html#a9d5758c091cc26b610b52ce5b6db5207',1,'pesieve::ModulesCache']]], + ['loadeddata_13',['loadedData',['../classpesieve_1_1_mem_page_data.html#a1a846ed452227d685a50a72ea516d0f9',1,'pesieve::MemPageData']]], + ['loadedsection_14',['loadedSection',['../classpesieve_1_1_pe_section.html#a81b7086cb5282d2a4fbd7f31353d144e',1,'pesieve::PeSection']]], + ['loadedsize_15',['loadedSize',['../classpesieve_1_1_pe_section.html#a45e6b2d32b562e2feb8cd5bb33ac6eb2',1,'pesieve::PeSection']]], + ['loadfullimage_16',['loadFullImage',['../classpesieve_1_1_remote_module_data.html#aae5bff1125a636a7faf7052ae32169e4',1,'pesieve::RemoteModuleData']]], + ['loadheader_17',['loadHeader',['../classpesieve_1_1_remote_module_data.html#a457911397fddaf4d660cf8330a00bb20',1,'pesieve::RemoteModuleData']]], + ['loadimportslist_18',['loadImportsList',['../classpesieve_1_1_module_data.html#acad74839a2978c3465c09bb93a3a2dc5',1,'pesieve::ModuleData::loadImportsList()'],['../classpesieve_1_1_remote_module_data.html#a4a7d767d81581e48f429f57286462406',1,'pesieve::RemoteModuleData::loadImportsList()']]], + ['loadimportthunks_19',['loadImportThunks',['../classpesieve_1_1_module_data.html#af0313c259e26056468c62b7b0aee5399',1,'pesieve::ModuleData']]], + ['loadmappedname_20',['loadMappedName',['../classpesieve_1_1_mem_page_data.html#a0b0278c8ee2cd31e5d36cec1a08edeef',1,'pesieve::MemPageData']]], + ['loadmodulename_21',['loadModuleName',['../classpesieve_1_1_mem_page_data.html#a683ee088e6b736f33491d54243a5b6a4',1,'pesieve::MemPageData::loadModuleName()'],['../classpesieve_1_1_module_data.html#afe5c22949731e3387a32ce58d241df1c',1,'pesieve::ModuleData::loadModuleName()']]], + ['loadoriginal_22',['loadOriginal',['../classpesieve_1_1_module_data.html#a729adaeb197b9f1415ff35e98e24c203',1,'pesieve::ModuleData::loadOriginal()'],['../classpesieve_1_1_pe_section.html#ae0525b58e8fd1eb8426d5eb2ebe1d278',1,'pesieve::PeSection::loadOriginal()']]], + ['loadpatternfile_23',['loadPatternFile',['../classpesieve_1_1_pattern_matcher.html#a3eea8c3106af7207969fab70f2176844',1,'pesieve::PatternMatcher']]], + ['loadrelocatedfields_24',['loadRelocatedFields',['../classpesieve_1_1_module_data.html#a561bfce148fdcf705144537fa2739bc2',1,'pesieve::ModuleData']]], + ['loadremote_25',['loadRemote',['../classpesieve_1_1_pe_section.html#a2431e70802f32bfec22c3bf23a7a79d2',1,'pesieve::PeSection']]], + ['lock_26',['Lock',['../structpesieve_1_1util_1_1_mutex.html#a1d253302cb2cda6c5ea0b76192cd9e2f',1,'pesieve::util::Mutex']]], + ['long_5fpath_5fprefix_27',['LONG_PATH_PREFIX',['../path__converter_8cpp.html#a10ada049714deddcb7c882a173f62999',1,'path_converter.cpp']]], + ['longeststr_28',['longestStr',['../structpesieve_1_1_chunk_stats.html#a5a4a7722c336a239ceed6a087740936c',1,'pesieve::ChunkStats']]], + ['lpcontext_29',['lpContext',['../namespacepesieve_1_1util.html#a474e517f22ad667eca359f745537886b',1,'pesieve::util']]], + ['ltrim_30',['ltrim',['../namespacepesieve_1_1util.html#a0436803ad7df590457409147fa98fb1e',1,'pesieve::util']]] ]; diff --git a/search/variables_11.js b/search/variables_11.js index 8697c2a11..a218f74b0 100644 --- a/search/variables_11.js +++ b/search/variables_11.js @@ -24,10 +24,9 @@ var searchData= ['report_5fnone_21',['REPORT_NONE',['../classpesieve_1_1t__report__type.html#a5e5ae97a231a29dab3433dab0fcb3039',1,'pesieve::t_report_type']]], ['report_5fscanned_22',['REPORT_SCANNED',['../classpesieve_1_1t__report__type.html#a33b01a2ea93a8cd6dec70841f1320929',1,'pesieve::t_report_type']]], ['reportsbytype_23',['reportsByType',['../classpesieve_1_1_process_scan_report.html#a85b6e8a39ec43b08a4f534dbd3f0589e',1,'pesieve::ProcessScanReport']]], - ['ret_5faddr_24',['ret_addr',['../structpesieve_1_1__ctx__details.html#a4b5f5a030c362877e2772ab3493e0d6f',1,'pesieve::_ctx_details']]], - ['returned_5fhndl_25',['returned_hndl',['../structpesieve_1_1util_1_1t__refl__args.html#a2039cf10734a4e3f07e94e6068122729',1,'pesieve::util::t_refl_args']]], - ['returned_5fpid_26',['returned_pid',['../structpesieve_1_1util_1_1t__refl__args.html#a7e95cffd1d650f477bb1d64377f4f6d7',1,'pesieve::util::t_refl_args']]], - ['rip_27',['rip',['../structpesieve_1_1__ctx__details.html#a6dc0bc061045467c3d71b6644adf68b4',1,'pesieve::_ctx_details']]], - ['rsp_28',['rsp',['../structpesieve_1_1__ctx__details.html#ab19759b888e6034d29dcaf6cedeed9bd',1,'pesieve::_ctx_details']]], - ['rva_29',['rva',['../classpesieve_1_1_pe_section.html#abb3723c684e695788cedc1654463b409',1,'pesieve::PeSection']]] + ['returned_5fhndl_24',['returned_hndl',['../structpesieve_1_1util_1_1t__refl__args.html#a2039cf10734a4e3f07e94e6068122729',1,'pesieve::util::t_refl_args']]], + ['returned_5fpid_25',['returned_pid',['../structpesieve_1_1util_1_1t__refl__args.html#a7e95cffd1d650f477bb1d64377f4f6d7',1,'pesieve::util::t_refl_args']]], + ['rip_26',['rip',['../structpesieve_1_1__ctx__details.html#a6dc0bc061045467c3d71b6644adf68b4',1,'pesieve::_ctx_details']]], + ['rsp_27',['rsp',['../structpesieve_1_1__ctx__details.html#ab19759b888e6034d29dcaf6cedeed9bd',1,'pesieve::_ctx_details']]], + ['rva_28',['rva',['../classpesieve_1_1_pe_section.html#abb3723c684e695788cedc1654463b409',1,'pesieve::PeSection']]] ]; diff --git a/search/variables_12.js b/search/variables_12.js index 96dd9d984..76f353a1b 100644 --- a/search/variables_12.js +++ b/search/variables_12.js @@ -10,34 +10,35 @@ var searchData= ['sectionrva_7',['sectionRVA',['../classpesieve_1_1_patch_analyzer.html#a34eb7c1430a1851749e5e096e9a2dbfa',1,'pesieve::PatchAnalyzer']]], ['sectiontoresult_8',['sectionToResult',['../classpesieve_1_1_code_scan_report.html#ade146d4d6dff33f669825e68d2d035da',1,'pesieve::CodeScanReport']]], ['settings_9',['settings',['../structpesieve_1_1_chunk_stats.html#a1268301237205e183a7fd2d097c70397',1,'pesieve::ChunkStats']]], - ['shellc_5fcount_10',['SHELLC_COUNT',['../classpesieve_1_1t__shellc__mode.html#abb24e6cbf35bbad15709d7b7c4d21c71',1,'pesieve::t_shellc_mode']]], - ['shellc_5fnone_11',['SHELLC_NONE',['../classpesieve_1_1t__shellc__mode.html#a7d4e9c7bdc63e28079f0a663287371aa',1,'pesieve::t_shellc_mode']]], - ['shellc_5fpatterns_12',['SHELLC_PATTERNS',['../classpesieve_1_1t__shellc__mode.html#a4371c512776afe9e6faeac818be15c14',1,'pesieve::t_shellc_mode']]], - ['shellc_5fpatterns_5fand_5fstats_13',['SHELLC_PATTERNS_AND_STATS',['../classpesieve_1_1t__shellc__mode.html#a16c88cc8e50ca3b6a8e08942d93475f1',1,'pesieve::t_shellc_mode']]], - ['shellc_5fpatterns_5for_5fstats_14',['SHELLC_PATTERNS_OR_STATS',['../classpesieve_1_1t__shellc__mode.html#a7ed46ef5720148741ee3d9d1f416694a',1,'pesieve::t_shellc_mode']]], - ['shellc_5fstats_15',['SHELLC_STATS',['../classpesieve_1_1t__shellc__mode.html#a67ddfa30a058f878421d277af59fbf2e',1,'pesieve::t_shellc_mode']]], - ['shellcode_16',['shellcode',['../structparams.html#a5063529cd6e6950334929d22164d3868',1,'params::shellcode'],['../namespacedemo.html#a6cdb502544cf88590852419885d95c92',1,'demo.shellcode']]], - ['size_17',['size',['../structpesieve_1_1_chunk_stats.html#a1a99134b17150d91a46a5a3a669063bc',1,'pesieve::ChunkStats::size'],['../structpesieve_1_1__t__pattern.html#a5f8a13e6e7fa8367d83bb9306ccca9d8',1,'pesieve::_t_pattern::size'],['../structpesieve_1_1util_1_1__mem__region__info.html#a5b8ade2cf0b8931e4f81b98ae2bfdac5',1,'pesieve::util::_mem_region_info::size']]], - ['skipped_18',['skipped',['../structreport.html#aa49ebcf3170fe05413a02a2af0ef5d9b',1,'report']]], - ['snapshothandle_19',['SnapshotHandle',['../namespacepesieve_1_1util.html#a6af9e73116d4d74647d319a492b721b0',1,'pesieve::util']]], - ['stack_5fframe_20',['stack_frame',['../struct__t__stack__enum__params.html#afd374d69c557b225099cff673e6ab6d7',1,'_t_stack_enum_params']]], - ['stackframescount_21',['stackFramesCount',['../structpesieve_1_1__ctx__details.html#aabca56adbcd0155923d8e6b0e62599c5',1,'pesieve::_ctx_details']]], - ['start_22',['start',['../classpesieve_1_1_scanned_module.html#a1257d00fc075f58c68a2f2f3ee2580c3',1,'pesieve::ScannedModule']]], - ['start_5faddr_23',['start_addr',['../structpesieve_1_1util_1_1__thread__info.html#a2d408cca43d2e48530d63c394755e96b',1,'pesieve::util::_thread_info']]], - ['start_5fva_24',['start_va',['../classpesieve_1_1_mem_page_data.html#aa47136298a2aecc8cc011162cf7a0571',1,'pesieve::MemPageData']]], - ['startcontext_25',['StartContext',['../namespacepesieve_1_1util.html#a867430ba8efef3a8f89e826a34791db1',1,'pesieve::util']]], - ['startoffset_26',['startOffset',['../classpesieve_1_1_i_a_t_thunks_series.html#a2c8fb26493bbda8f2c53d4b28c19531a',1,'pesieve::IATThunksSeries']]], - ['startroutine_27',['StartRoutine',['../namespacepesieve_1_1util.html#a243a5bb6446feaa7c25fa56debfc0384',1,'pesieve::util']]], - ['startrva_28',['startRva',['../classpesieve_1_1_patch_list_1_1_patch.html#a7b946d650da353c56690ff150eb4a82c',1,'pesieve::PatchList::Patch']]], - ['state_29',['state',['../structpesieve_1_1util_1_1__thread__info__ext.html#a64f10518106ade775aecd7f5c2caaf65',1,'pesieve::util::_thread_info_ext']]], - ['stats_30',['stats',['../classpesieve_1_1_thread_scan_report.html#a00f0b36826c124dc6be154f0cdeb7f83',1,'pesieve::ThreadScanReport::stats'],['../classpesieve_1_1_working_set_scan_report.html#a2b63bfed29add17e9db10f21936cedc0',1,'pesieve::WorkingSetScanReport::stats']]], - ['status_31',['status',['../classpesieve_1_1_module_scan_report.html#a10b0bdf16cb9e7af32e1ab9b35532f68',1,'pesieve::ModuleScanReport']]], - ['stop_5fva_32',['stop_va',['../classpesieve_1_1_mem_page_data.html#a7c151bd819b2444eb7e93c92fcd4f8ce',1,'pesieve::MemPageData']]], - ['storedfunc_33',['storedFunc',['../classpesieve_1_1_i_a_t_scan_report.html#a7a631d5a508e52d214764f5d25490b2e',1,'pesieve::IATScanReport']]], - ['stringscount_34',['stringsCount',['../structpesieve_1_1_chunk_stats.html#a41e1a3748f347a69f1db454cb3dd2651',1,'pesieve::ChunkStats']]], - ['susp_5faddr_35',['susp_addr',['../classpesieve_1_1_thread_scan_report.html#a5a930aaa32e9de46d95b25018a373cbc',1,'pesieve::ThreadScanReport']]], - ['suspicious_36',['suspicious',['../structreport.html#a5ee5e4dbcf6777455b2b32b1529d4980',1,'report']]], - ['symbols_37',['symbols',['../classpesieve_1_1_process_scanner.html#ac9a6ee9cd3632a5ccd3f03742700959f',1,'pesieve::ProcessScanner::symbols'],['../classpesieve_1_1_thread_scanner.html#ad455f81b20ec49dc2968d6f2db67ae13',1,'pesieve::ThreadScanner::symbols']]], - ['sys_5fstart_5faddr_38',['sys_start_addr',['../structpesieve_1_1util_1_1__thread__info__ext.html#a015d9ec862bebffabeeea74cc94c6c03',1,'pesieve::util::_thread_info_ext']]], - ['szmodname_39',['szModName',['../classpesieve_1_1_module_data.html#ab7463bd2db1ce6343e1be66600c48cd8',1,'pesieve::ModuleData']]] + ['shccandidates_10',['shcCandidates',['../structpesieve_1_1__ctx__details.html#a44ca7a32918f0eab5a8d9cf14080e0c0',1,'pesieve::_ctx_details']]], + ['shellc_5fcount_11',['SHELLC_COUNT',['../classpesieve_1_1t__shellc__mode.html#abb24e6cbf35bbad15709d7b7c4d21c71',1,'pesieve::t_shellc_mode']]], + ['shellc_5fnone_12',['SHELLC_NONE',['../classpesieve_1_1t__shellc__mode.html#a7d4e9c7bdc63e28079f0a663287371aa',1,'pesieve::t_shellc_mode']]], + ['shellc_5fpatterns_13',['SHELLC_PATTERNS',['../classpesieve_1_1t__shellc__mode.html#a4371c512776afe9e6faeac818be15c14',1,'pesieve::t_shellc_mode']]], + ['shellc_5fpatterns_5fand_5fstats_14',['SHELLC_PATTERNS_AND_STATS',['../classpesieve_1_1t__shellc__mode.html#a16c88cc8e50ca3b6a8e08942d93475f1',1,'pesieve::t_shellc_mode']]], + ['shellc_5fpatterns_5for_5fstats_15',['SHELLC_PATTERNS_OR_STATS',['../classpesieve_1_1t__shellc__mode.html#a7ed46ef5720148741ee3d9d1f416694a',1,'pesieve::t_shellc_mode']]], + ['shellc_5fstats_16',['SHELLC_STATS',['../classpesieve_1_1t__shellc__mode.html#a67ddfa30a058f878421d277af59fbf2e',1,'pesieve::t_shellc_mode']]], + ['shellcode_17',['shellcode',['../structparams.html#a5063529cd6e6950334929d22164d3868',1,'params::shellcode'],['../namespacedemo.html#a6cdb502544cf88590852419885d95c92',1,'demo.shellcode']]], + ['size_18',['size',['../structpesieve_1_1_chunk_stats.html#a1a99134b17150d91a46a5a3a669063bc',1,'pesieve::ChunkStats::size'],['../structpesieve_1_1__t__pattern.html#a5f8a13e6e7fa8367d83bb9306ccca9d8',1,'pesieve::_t_pattern::size'],['../structpesieve_1_1util_1_1__mem__region__info.html#a5b8ade2cf0b8931e4f81b98ae2bfdac5',1,'pesieve::util::_mem_region_info::size']]], + ['skipped_19',['skipped',['../structreport.html#aa49ebcf3170fe05413a02a2af0ef5d9b',1,'report']]], + ['snapshothandle_20',['SnapshotHandle',['../namespacepesieve_1_1util.html#a6af9e73116d4d74647d319a492b721b0',1,'pesieve::util']]], + ['stack_5fframe_21',['stack_frame',['../struct__t__stack__enum__params.html#afd374d69c557b225099cff673e6ab6d7',1,'_t_stack_enum_params']]], + ['stackframescount_22',['stackFramesCount',['../structpesieve_1_1__ctx__details.html#aabca56adbcd0155923d8e6b0e62599c5',1,'pesieve::_ctx_details']]], + ['start_23',['start',['../classpesieve_1_1_scanned_module.html#a1257d00fc075f58c68a2f2f3ee2580c3',1,'pesieve::ScannedModule']]], + ['start_5faddr_24',['start_addr',['../structpesieve_1_1util_1_1__thread__info.html#a2d408cca43d2e48530d63c394755e96b',1,'pesieve::util::_thread_info']]], + ['start_5fva_25',['start_va',['../classpesieve_1_1_mem_page_data.html#aa47136298a2aecc8cc011162cf7a0571',1,'pesieve::MemPageData']]], + ['startcontext_26',['StartContext',['../namespacepesieve_1_1util.html#a867430ba8efef3a8f89e826a34791db1',1,'pesieve::util']]], + ['startoffset_27',['startOffset',['../classpesieve_1_1_i_a_t_thunks_series.html#a2c8fb26493bbda8f2c53d4b28c19531a',1,'pesieve::IATThunksSeries']]], + ['startroutine_28',['StartRoutine',['../namespacepesieve_1_1util.html#a243a5bb6446feaa7c25fa56debfc0384',1,'pesieve::util']]], + ['startrva_29',['startRva',['../classpesieve_1_1_patch_list_1_1_patch.html#a7b946d650da353c56690ff150eb4a82c',1,'pesieve::PatchList::Patch']]], + ['state_30',['state',['../structpesieve_1_1util_1_1__thread__info__ext.html#a64f10518106ade775aecd7f5c2caaf65',1,'pesieve::util::_thread_info_ext']]], + ['stats_31',['stats',['../classpesieve_1_1_thread_scan_report.html#a00f0b36826c124dc6be154f0cdeb7f83',1,'pesieve::ThreadScanReport::stats'],['../classpesieve_1_1_working_set_scan_report.html#a2b63bfed29add17e9db10f21936cedc0',1,'pesieve::WorkingSetScanReport::stats']]], + ['status_32',['status',['../classpesieve_1_1_module_scan_report.html#a10b0bdf16cb9e7af32e1ab9b35532f68',1,'pesieve::ModuleScanReport']]], + ['stop_5fva_33',['stop_va',['../classpesieve_1_1_mem_page_data.html#a7c151bd819b2444eb7e93c92fcd4f8ce',1,'pesieve::MemPageData']]], + ['storedfunc_34',['storedFunc',['../classpesieve_1_1_i_a_t_scan_report.html#a7a631d5a508e52d214764f5d25490b2e',1,'pesieve::IATScanReport']]], + ['stringscount_35',['stringsCount',['../structpesieve_1_1_chunk_stats.html#a41e1a3748f347a69f1db454cb3dd2651',1,'pesieve::ChunkStats']]], + ['susp_5faddr_36',['susp_addr',['../classpesieve_1_1_thread_scan_report.html#a5a930aaa32e9de46d95b25018a373cbc',1,'pesieve::ThreadScanReport']]], + ['suspicious_37',['suspicious',['../structreport.html#a5ee5e4dbcf6777455b2b32b1529d4980',1,'report']]], + ['symbols_38',['symbols',['../classpesieve_1_1_process_scanner.html#ac9a6ee9cd3632a5ccd3f03742700959f',1,'pesieve::ProcessScanner::symbols'],['../classpesieve_1_1_thread_scanner.html#ad455f81b20ec49dc2968d6f2db67ae13',1,'pesieve::ThreadScanner::symbols']]], + ['sys_5fstart_5faddr_39',['sys_start_addr',['../structpesieve_1_1util_1_1__thread__info__ext.html#a015d9ec862bebffabeeea74cc94c6c03',1,'pesieve::util::_thread_info_ext']]], + ['szmodname_40',['szModName',['../classpesieve_1_1_module_data.html#ab7463bd2db1ce6343e1be66600c48cd8',1,'pesieve::ModuleData']]] ]; diff --git a/search/variables_b.js b/search/variables_b.js index 0c143b96e..62c663236 100644 --- a/search/variables_b.js +++ b/search/variables_b.js @@ -1,12 +1,13 @@ var searchData= [ - ['laststr_0',['lastStr',['../structpesieve_1_1_chunk_stats.html#aa3dd6619cda8fd6d7e6a0471a2ab9c26',1,'pesieve::ChunkStats']]], - ['lastusage_1',['lastUsage',['../structpesieve_1_1_cached_module.html#ac346042e22490dec922835547a992e05',1,'pesieve::CachedModule']]], - ['length_2',['length',['../struct___p_a_r_a_m___s_t_r_i_n_g.html#a7996767bb0f2ac6ccfc42d6ddb210bcf',1,'_PARAM_STRING::length'],['../namespacedemo.html#abc3711f6440e69ac690f99e61099b9d2',1,'demo.length']]], - ['lib_3',['lib',['../namespacepesieve.html#aca0538d4001454cd1ec5d9c2df390ac8',1,'pesieve']]], - ['loadeddata_4',['loadedData',['../classpesieve_1_1_mem_page_data.html#a1a846ed452227d685a50a72ea516d0f9',1,'pesieve::MemPageData']]], - ['loadedsection_5',['loadedSection',['../classpesieve_1_1_pe_section.html#a81b7086cb5282d2a4fbd7f31353d144e',1,'pesieve::PeSection']]], - ['loadedsize_6',['loadedSize',['../classpesieve_1_1_pe_section.html#a45e6b2d32b562e2feb8cd5bb33ac6eb2',1,'pesieve::PeSection']]], - ['longeststr_7',['longestStr',['../structpesieve_1_1_chunk_stats.html#a5a4a7722c336a239ceed6a087740936c',1,'pesieve::ChunkStats']]], - ['lpcontext_8',['lpContext',['../namespacepesieve_1_1util.html#a474e517f22ad667eca359f745537886b',1,'pesieve::util']]] + ['last_5fret_0',['last_ret',['../structpesieve_1_1__ctx__details.html#a98c61b583bcc9251354d2e199b1c5523',1,'pesieve::_ctx_details']]], + ['laststr_1',['lastStr',['../structpesieve_1_1_chunk_stats.html#aa3dd6619cda8fd6d7e6a0471a2ab9c26',1,'pesieve::ChunkStats']]], + ['lastusage_2',['lastUsage',['../structpesieve_1_1_cached_module.html#ac346042e22490dec922835547a992e05',1,'pesieve::CachedModule']]], + ['length_3',['length',['../struct___p_a_r_a_m___s_t_r_i_n_g.html#a7996767bb0f2ac6ccfc42d6ddb210bcf',1,'_PARAM_STRING::length'],['../namespacedemo.html#abc3711f6440e69ac690f99e61099b9d2',1,'demo.length']]], + ['lib_4',['lib',['../namespacepesieve.html#aca0538d4001454cd1ec5d9c2df390ac8',1,'pesieve']]], + ['loadeddata_5',['loadedData',['../classpesieve_1_1_mem_page_data.html#a1a846ed452227d685a50a72ea516d0f9',1,'pesieve::MemPageData']]], + ['loadedsection_6',['loadedSection',['../classpesieve_1_1_pe_section.html#a81b7086cb5282d2a4fbd7f31353d144e',1,'pesieve::PeSection']]], + ['loadedsize_7',['loadedSize',['../classpesieve_1_1_pe_section.html#a45e6b2d32b562e2feb8cd5bb33ac6eb2',1,'pesieve::PeSection']]], + ['longeststr_8',['longestStr',['../structpesieve_1_1_chunk_stats.html#a5a4a7722c336a239ceed6a087740936c',1,'pesieve::ChunkStats']]], + ['lpcontext_9',['lpContext',['../namespacepesieve_1_1util.html#a474e517f22ad667eca359f745537886b',1,'pesieve::util']]] ]; diff --git a/structpesieve_1_1__ctx__details-members.html b/structpesieve_1_1__ctx__details-members.html index cb8e952a6..f65e4e227 100644 --- a/structpesieve_1_1__ctx__details-members.html +++ b/structpesieve_1_1__ctx__details-members.html @@ -100,11 +100,12 @@ init(bool _is64b=false, ULONGLONG _rip=0, ULONGLONG _rsp=0, ULONGLONG _rbp=0, ULONGLONG _ret_addr=0)pesieve::_ctx_detailsinline is64bpesieve::_ctx_details is_managedpesieve::_ctx_details - rbppesieve::_ctx_details - ret_addrpesieve::_ctx_details + last_retpesieve::_ctx_details + rbppesieve::_ctx_details rippesieve::_ctx_details rsppesieve::_ctx_details - stackFramesCountpesieve::_ctx_details + shcCandidatespesieve::_ctx_details + stackFramesCountpesieve::_ctx_details