Dumps memory components from specific processes or from all processes currently running. Supports creation and use of a clean-hash database, so that dumping of all the clean files such as kernel32.dll can be skipped.

PE-sieve is described as 'Scans a given process, searching for the modules containing in-memory code modifications. When found, it dumps the modified PE. Detects inline hooks, hollowed processes, Process Doppelgänging etc. Can be used for unpacking malware' and is a process monitoring tool in the development category. There are three alternatives to PE-sieve for Windows, Linux, Python and Mac. The best PE-sieve alternative is Process Dump, which is both free and Open Source. Other great apps like PE-sieve are LiveDump and PyMemoryEditor.
Dumps memory components from specific processes or from all processes currently running. Supports creation and use of a clean-hash database, so that dumping of all the clean files such as kernel32.dll can be skipped.

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python.
