Using: PE-sieve v0.4.0
https://github.com/hasherezade/pe-sieve/releases/tag/v0.4.0
FEATURE
- Added new parameter:
/etw
(64-bit only) - allows to run HH as an ETW listener. The types of listened events can be enabled/disabled by editingHH_ETWProfile.ini
- Improved caching. From now modules caching is enabled by default when run in continuous scan mode (
/loop
or/etw
). Settings can be changed via parameter/cache
. - Updated CLI to follow the changes in PE-sieve. Support new parameters:
/rebase
and/report
.
BUGFIX
- Fixed crashing at the end of scan (occurring in 32-bit HH)
- Other small fixes and improvements