Hollows_Hunter
Windows

Hollows_Hunter 0.4.1.1

Command line application based on the passive memory scanner PE-sieve.

Download Freeware1.2 MB
Description

Hollows_Hunter is a command-line application based on the passive memory scanner PE-sieve. Its main function is to identify and dump various types of potentially malicious implants, such as replaced/embedded PE, shellcodes, hooks, and patches in memory.

Main Features:

Advanced Process Selection: Unlike PE-sieve, which allows selecting processes only by PID (process identifier), Hollows Hunter offers the possibility to choose processes based on various criteria:

  • List of PIDs
  • List of process names
  • Creation time (relative to the moment of executing Hollows Hunter)

Complete Scanning: If no specific target is selected, the software scans all available processes in the system.

Continuous Scanning: Hollows Hunter can be configured to perform continuous memory scanning using the /loop argument or run as an ETW (Event Tracing for Windows) listener in /etw mode (64-bit version only).

With these features, Hollows Hunter becomes a powerful tool for identifying malicious implants in memory, making it essential for security analysis in Windows systems.

Old versions

File security

0/72 engines flagged the file in the recorded scan.

Scan date: 09/13/2025

SHA-256: 56a58a8bbf2cec9a5c7c68129e8863af6181fb51dfc25226f1a756aba66b4707

View report on VirusTotal ↗

The scan result does not replace normal precautions when installing files.
Found a problem on this page?Tell the team about broken links, versions or incorrect information.
Advertising

Related