Package rekall :: Package plugins :: Package windows :: Package malware :: Module apihooks
[frames] | no frames]

Module apihooks

source code

Classes
  DecodingError
Raised when unable to decode an instruction.
  HookHeuristic
A Hook heuristic detects possible hooks.
  CheckPEHooks
Checks a pe file mapped into memory for hooks.
  EATHooks
Detect EAT hooks in process and kernel memory
  TestEATHooks
  IATHooks
Detect IAT/EAT hooks in process and kernel memory
  TestIATHooks
  InlineHooks
Detect API hooks in process and kernel memory
  TestInlineHooks
Variables
  __package__ = 'rekall.plugins.windows.malware'