v0.3.4
Updated PE-sieve (v0.3.4):
https://github.com/hasherezade/pe-sieve/releases/tag/v0.3.4
FEATURE
- Supported changes in the implementation of
/mignore
- Supported new PE-sieve param:
/threads
: enabling scan of the threads' callstack . This is another layer of shellcode detection, allowing to capture "sleeping beacons", and others, decrypted just before the execution.