hollows_hunter - A process scanner detecting and dump hollowed PE modules.

hollows_hunter – A process scanner detecting and dump hollowed PE modules.

hollows_hunter is a process scanner detecting and dumping hollowed PE modules. it Uses PE-sieve (DLL version): PE-sieve is n open source tool based on libpeconv. It scans a given process, searching for manually loaded or modified modules. When found, it dumps the modified/suspicious PE along with a report in JSON format, detailing about the found indicator.

hollows_hunter v0.1

Dependencies:
+ Visual C++

Use and Download:

Source: https://github.com/hasherezade