
PE-sieve用のGolangバインディング
PE-sieve 用の Golang バインディングです。
プロジェクトディレクトリ内、または環境変数 PESIEVE_DIR で指定されたパスに、サポート対象バージョンの pe-sieve32.dll、pe-sieve64.dll が存在する必要があります。
PE-sieve API 向けに、以下のラッパーを公開しています:
PESieveVersion uint32
func PESieveHelp()
func PESieveScan(pp PEsieveParams) PEsieveReport
func PESieveScanEx(pp PEsieveParams, rtype t_report_type, jsonMaxSize uint32) (PEsieveReport, string, uint32)
package main
import (
"fmt"
"syscall"
"github.com/hasherezade/pesieve-go"
)
// Scan the current process
func ScanThis(myPid uint32) string {
var mods = string("kernel32.dll")
ignoredBuf := make([]byte, len(mods)+1)
copy(ignoredBuf[:], mods)
// Set up the scan parameters
pp := pesieve.PEsieveParams{
Pid: myPid,
Threads: true,
Shellcode: pesieve.SHELLC_PATTERNS,
Quiet: true,
JsonLvl: pesieve.JSON_DETAILS2,
ModulesIgnored : pesieve.PARAM_STRING { Buffer: ignoredBuf, Length: uint32(len(mods)) },
}
copy(pp.OutputDir[:], "MyDemoDir")
const rtype = pesieve.REPORT_ALL
const jsonMaxLen = 2000
_, json, _ := pesieve.PESieveScanEx(pp, rtype, jsonMaxLen)
return json
}
func main() {
message := ScanThis( uint32(syscall.Getpid()) )
fmt.Println(message)
}