PE-sieve scans a given process, searching for the modules containing in-memory code modifications. When found, it dumps the modified PE. Detects inline hooks, hollowed processes, Process Doppelgänging etc. Can be used for unpacking malware.

PE-sieve is the most popular Windows alternative to Process Dump.
PE-sieve is the most popular Open Source & free alternative to Process Dump.
- PE-sieve is Free and Open Source


