{"id":13453755,"url":"https://github.com/hasherezade/hollows_hunter","last_synced_at":"2025-05-14T08:06:28.525Z","repository":{"id":39746804,"uuid":"117128578","full_name":"hasherezade/hollows_hunter","owner":"hasherezade","description":"Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).","archived":false,"fork":false,"pushed_at":"2025-03-30T17:10:27.000Z","size":15321,"stargazers_count":2141,"open_issues_count":1,"forks_count":269,"subscribers_count":65,"default_branch":"master","last_synced_at":"2025-04-11T02:51:55.852Z","etag":null,"topics":["anti-malware","malware-analysis","malware-detection","memory-forensics","pe-sieve"],"latest_commit_sha":null,"homepage":"https://github.com/hasherezade/hollows_hunter/wiki","language":"C","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-2-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/hasherezade.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2018-01-11T17:07:17.000Z","updated_at":"2025-04-10T11:43:26.000Z","dependencies_parsed_at":"2023-02-16T00:31:09.382Z","dependency_job_id":"69548e6a-8a5f-4254-bdcc-6f6ed82b0655","html_url":"https://github.com/hasherezade/hollows_hunter","commit_stats":null,"previous_names":[],"tags_count":46,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hasherezade%2Fhollows_hunter","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hasherezade%2Fhollows_hunter/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hasherezade%2Fhollows_hunter/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/hasherezade%2Fhollows_hunter/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/hasherezade","download_url":"https://codeload.github.com/hasherezade/hollows_hunter/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":254101616,"owners_count":22014909,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["anti-malware","malware-analysis","malware-detection","memory-forensics","pe-sieve"],"created_at":"2024-07-31T08:00:46.632Z","updated_at":"2025-05-14T08:06:23.505Z","avatar_url":"https://github.com/hasherezade.png","language":"C","funding_links":[],"categories":["Threat Detection and Hunting","C","C (286)","\u003ca id=\"8f92ead9997a4b68d06a9acf9b01ef63\"\u003e\u003c/a\u003e扫描器\u0026\u0026安全扫描\u0026\u0026App扫描\u0026\u0026漏洞扫描","Other Lists","malware-analysis","\u003ca id=\"132036452bfacf61471e3ea0b7bf7a55\"\u003e\u003c/a\u003e工具","Operating Systems","🔧 Packages"],"sub_categories":["Tools","\u003ca id=\"de63a029bda6a7e429af272f291bb769\"\u003e\u003c/a\u003e未分类-Scanner","🛡️ DFIR:","Windows","⚡ Analyzing"],"readme":"# hollows_hunter\n![](./logo/logo2_128.png)\n\n[![Build status](https://ci.appveyor.com/api/projects/status/nsc2eux5986y1shq?svg=true)](https://ci.appveyor.com/project/hasherezade/hollows-hunter)\n[![Codacy Badge](https://api.codacy.com/project/badge/Grade/0c149fcd62084f96ac0c131e4473dbdf)](https://app.codacy.com/gh/hasherezade/hollows_hunter/dashboard?branch=master)\n[![Commit activity](https://img.shields.io/github/commit-activity/m/hasherezade/hollows_hunter)](https://github.com/hasherezade/hollows_hunter/commits)\n[![Last Commit](https://img.shields.io/github/last-commit/hasherezade/hollows_hunter/master)](https://github.com/hasherezade/hollows_hunter/commits)\n\n[![GitHub release](https://img.shields.io/github/release/hasherezade/hollows_hunter.svg)](https://github.com/hasherezade/hollows_hunter/releases)\n[![GitHub release date](https://img.shields.io/github/release-date/hasherezade/hollows_hunter?color=blue)](https://github.com/hasherezade/hollows_hunter/releases)\n[![Github All Releases](https://img.shields.io/github/downloads/hasherezade/hollows_hunter/total.svg)](https://github.com/hasherezade/hollows_hunter/releases)\n[![Github Latest Release](https://img.shields.io/github/downloads/hasherezade/hollows_hunter/latest/total.svg)](https://github.com/hasherezade/hollows_hunter/releases)\n\n[![License](https://img.shields.io/badge/License-BSD%202--Clause-blue.svg)](https://github.com/hasherezade/hollows_hunter/blob/master/LICENSE)\n[![Platform Badge](https://img.shields.io/badge/Windows-0078D6?logo=windows)](https://github.com/hasherezade/hollows_hunter)\n\nHollows Hunter is a command-line application based on [PE-sieve](https://github.com/hasherezade/pe-sieve.git) passive memory scanner. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches). While in case of PE-sieve you can select the process only by its PID, Hollows Hunter allows to select them by various criteria, such as:\n+ list of PIDs\n+ list of names\n+ the time of creation (relatively to the Hollows Hunter execution time)\n\nIf no specific target is selected, it proceeds to scan all available processes.\n\nHollows Hunter allows also for continuous memory scanning, via `/loop` argument, or by being run as an ETW listener: in `/etw` mode (64-bit version only).\n\n\u003e [!IMPORTANT]  \n\u003e The available arguments are documented on [Wiki](https://github.com/hasherezade/hollows_hunter/wiki). They can also be listed using the argument `/help`.\n\n📦 Uses: [PE-sieve](https://github.com/hasherezade/pe-sieve.git) (the [library version](https://github.com/hasherezade/pe-sieve/wiki/2.-How-to-build)).\n\n❓ [PE-sieve FAQ - Frequently Asked Questions](https://github.com/hasherezade/pe-sieve/wiki/1.-FAQ)\n\n📖 [Read Wiki](https://github.com/hasherezade/hollows_hunter/wiki)\n\n\n## Clone\n\nUse recursive clone to get the repo together with all the submodules:\n\n```console\ngit clone --recursive https://github.com/hasherezade/hollows_hunter.git\n```\n\n## Builds\n\nDownload the latest [release](https://github.com/hasherezade/hollows_hunter/releases), or [read more](https://github.com/hasherezade/hollows_hunter/wiki#download).\n\n![](https://community.chocolatey.org/favicon.ico) Available also via [Chocolatey](https://community.chocolatey.org/packages/hollowshunter)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhasherezade%2Fhollows_hunter","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fhasherezade%2Fhollows_hunter","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhasherezade%2Fhollows_hunter/lists"}