PE-sieve scans a given process, searching for the modules containing in-memory code modifications. When found, it dumps the modified PE. Detects inline hooks, hollowed processes, Process Doppelgänging etc. Can be used for unpacking malware.
Cost / License
- Free
- Open Source (BSD-2-Clause)
Application type
Platforms
- Windows
Poland
EU






