ENNAENNA

PE-sieve

BSD-2-Clause

馃敩 Digital ForensicsC++

PE-sieve is a C++ based tool that scans active processes for in-memory anomalies such as process hollowing, code injection, and hooking. It is designed to identify and report suspicious modifications that could indicate malware presence or process tampering. PE-sieve is valuable for memory forensics and incident response, as it helps analysts detect and analyze advanced threats that manipulate process memory.

3.6kstars
471forks
9issues
Updated 1mo ago
+I use this

Tags

process-scanningmemory-forensicscode-injectionmalware-detectionanti-malwarehookinglibpeconvmalware-analysispe-analyzerpe-dumperpe-formatpe-sieveprocess-analyzerscans

Community Reviews

More in Digital Forensics