Skip to content
 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 

Repository files navigation

RunPE-Detecter

RunPE/ProcessHollowing/ProcessReplacement is one of the most common attack methods used by Malware Authors. This type of Memory-Resident malware is actually easy to detect if correct tools/knowledge is used. RunPE-Detector scans all the processes running and compares the PE headers of the running process with its counter image on disk.

About

RunPE Detecter

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages