EN
ENNA

PE-sieve

BSD-2-Clause

🔬 Digital Forensics · C++

PE-sieve is a C++ based tool that scans active processes for in-memory anomalies such as process hollowing, code injection, and hooking. It is designed to identify and report suspicious modifications that could indicate malware presence or process tampering. PE-sieve is valuable for memory forensics and incident response, as it helps analysts detect and analyze advanced threats that manipulate process memory.

3.6kstars
468forks
9issues
Updated 4d ago

Tags

process-scanningmemory-forensicscode-injectionmalware-detectionanti-malwarehookinglibpeconvmalware-analysispe-analyzerpe-dumperpe-formatpe-sieveprocess-analyzerscans

More in Digital Forensics