Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
BSD 2-Clause "Simplified" License
3.01k
stars
421
forks
source link
Minidump of a detected process #43
Closed
hasherezade closed 4 years ago
Add a parameter allowing to make a minidump of the process detected as suspicious.