MCPcopy Create free account

hub / github.com/DFIR-ORC/dfir-orc / functions

Functions5,324 in github.com/DFIR-ORC/dfir-orc

↓ 4 callersFunctionCreateXmlReader
src/OrcLib/EmbeddedResource_Embed.cpp:68
↓ 4 callersMethodCritical
src/OrcLib/Log/Logger.h:346
↓ 4 callersMethodDataRelativeOffset
src/OrcLib/Filesystem/Ntfs/ShadowCopy/DiffAreaTableEntry.h:39
↓ 4 callersMethodDecompress
src/OrcLib/CompressAPIExtension.h:104
↓ 4 callersFunctionDefaultConfiguration
src/OrcCommand/Command/DD/DD.h:66
↓ 4 callersMethodEnumJournal
src/OrcLib/USNJournalWalker.cpp:218
↓ 4 callersMethodFirstBitmapOffset
src/OrcLib/Filesystem/Ntfs/ShadowCopy/CatalogEntry.h:124
↓ 4 callersMethodFirstDiffAreaTableOffset
src/OrcLib/Filesystem/Ntfs/ShadowCopy/CatalogEntry.h:120
↓ 4 callersMethodFlags
src/OrcLib/AttributeList.h:75
↓ 4 callersMethodFlush
src/OrcLib/Log/Logger.h:387
↓ 4 callersFunctionFormatResourceIdentifier
src/OrcCapsule/Cmd/CmdResource.cpp:486
↓ 4 callersMethodFreeCell
libération d'une cellule
src/OrcLib/HeapStorage.h:69
↓ 4 callersMethodGetAuthenticodeHash
src/OrcLib/FileFormat/PeParser.cpp:1009
↓ 4 callersMethodGetAvailableSize
src/OrcLib/CsvCruncher.h:107
↓ 4 callersMethodGetCurrentColumnID
src/OrcLib/CsvFileWriter.h:76
↓ 4 callersMethodGetDataAttribute
src/OrcLib/MFTRecord.cpp:619
↓ 4 callersMethodGetDefaultFileName
src/OrcLib/MFTRecord.h:71
↓ 4 callersMethodGetDeleteWhenDone
src/OrcLib/UploadMessage.h:74
↓ 4 callersFunctionGetFilePath
tests/OrcApacheOrcTest/orc_output.cpp:293
↓ 4 callersMethodGetHandle
tests/OrcLibTest/DiskExtentTest.h:36
↓ 4 callersMethodGetOrcTool
src/OrcLib/CommandNotification.h:128
↓ 4 callersMethodGetParentKey
src/OrcLib/RegistryWalker.cpp:74
↓ 4 callersMethodGetProfilingStatistics
src/OrcLib/FileFind.h:342
↓ 4 callersMethodGetRequest
src/OrcLib/UploadAgent.h:68
↓ 4 callersMethodGetScopedMatchProfiler
src/OrcLib/FileFind.h:137
↓ 4 callersMethodGetSha1
src/OrcCommand/Command/WolfLauncher/Outcome.h:137
↓ 4 callersFunctionHasInvalidFlag
src/OrcLib/Filesystem/FileAttribute.cpp:75
↓ 4 callersMethodHasNamedDataAttr
src/OrcLib/MFTRecord.h:68
↓ 4 callersMethodInfo
src/OrcLib/Log/Logger.h:219
↓ 4 callersMethodInitArchive
src/OrcLib/ZipCreate.cpp:218
↓ 4 callersMethodIsFAT12
src/OrcLib/Partition.cpp:44
↓ 4 callersMethodIsFAT16
src/OrcLib/Partition.cpp:49
↓ 4 callersMethodIsNonResident
src/OrcLib/MftRecordAttribute.h:108
↓ 4 callersMethodIsPresent
src/OrcLib/AttributeList.h:153
↓ 4 callersFunctionIsRangeValid
src/OrcLib/RegistryWalker.cpp:17
↓ 4 callersFunctionIsZstdArchive
src/OrcCapsule/Utilities/Compression.cpp:92
↓ 4 callersMethodLayerPosition
src/OrcLib/Filesystem/Ntfs/ShadowCopy/SnapshotInformation.h:39
↓ 4 callersFunctionNtError
src/OrcLib/Utils/Result.h:243
↓ 4 callersMethodNtOpenFile
src/OrcLib/NtDllExtension.h:55
↓ 4 callersMethodOpen
src/OrcLib/Log/FileSinkWin32.h:49
↓ 4 callersMethodOpenAllocatedDataStream
src/OrcLib/NTFSStream.cpp:74
↓ 4 callersMethodOutputPath
src/OrcCommand/Log/UtilitiesLogger.h:83
↓ 4 callersFunctionParseBacktraceLevel
src/OrcCommand/Log/UtilitiesLoggerConfiguration.cpp:206
↓ 4 callersFunctionParseLogLevel
src/OrcCommand/Log/UtilitiesLoggerConfiguration.cpp:189
↓ 4 callersFunctionParseShadowsParserOption
src/OrcCommand/Configuration/ShadowsParserOption.cpp:13
↓ 4 callersMethodPhysicalMemoryRequirement
src/OrcLib/CommandMessage.h:208
↓ 4 callersMethodPushInputFile
src/OrcLib/CommandMessage.cpp:125
↓ 4 callersMethodPushOutputDirectory
src/OrcLib/CommandMessage.cpp:184
↓ 4 callersFunctionRegisterCommonItems
src/OrcCommand/Log/UtilitiesLoggerConfiguration.cpp:97
↓ 4 callersMethodReset
src/OrcLib/Utils/StdStream/StandardOutput.cpp:31
↓ 4 callersFunctionRoundUpPow2
src/OrcLib/Utils/Round.h:33
↓ 4 callersMethodSeek
src/OrcLib/Stream/VolumeStreamReader.cpp:36
↓ 4 callersMethodSetCallback
src/OrcLib/Archive.cpp:73
↓ 4 callersMethodSetCompressionLevel
src/OrcLib/ZipCreate.cpp:162
↓ 4 callersFunctionSetFileSize
src/OrcLib/ArchiveAgent.cpp:23
↓ 4 callersMethodSetName
src/OrcCommand/Command/WolfLauncher/Outcome.h:57
↓ 4 callersFunctionSetOptionalString
src/OrcLib/Log/Syslog/SyslogMessage.cpp:19
↓ 4 callersMethodSetOriginFriendlyName
src/OrcLib/CommandExecute.h:207
↓ 4 callersMethodTake
src/OrcLib/Utils/StdStream/StreamRedirector.h:29
↓ 4 callersMethodTee
src/OrcLib/Utils/StdStream/Tee.h:20
↓ 4 callersFunctionToIdentifiersW
src/OrcLib/Filesystem/FileAttribute.cpp:196
↓ 4 callersFunctionToLevel
src/OrcLib/Log/Level.cpp:39
↓ 4 callersFunctionToResurrectRecordsMode
src/OrcLib/ResurrectRecordsMode.cpp:90
↓ 4 callersMethodToString
src/OrcLib/Utils/Threshold.h:69
↓ 4 callersFunctionToWString
src/OrcLib/Text/in_addr.cpp:148
↓ 4 callersMethodUnlock
src/OrcLib/CircularStorage.h:171
↓ 4 callersMethodUpdate
src/OrcCapsule/Utilities/Resource.cpp:292
↓ 4 callersFunctionUpdateOutcome
src/OrcCommand/Command/WolfLauncher/WolfLauncher_Run.cpp:129
↓ 4 callersMethodVersion
src/OrcLib/Filesystem/Ntfs/ShadowCopy/Node.h:42
↓ 4 callersFunctionWriteChunk
src/OrcLib/ByteStreamHelpers.h:300
↓ 4 callersMethodWriteFileInformation
src/OrcLib/FileInfo.cpp:367
↓ 4 callersMethodWriteFlags
src/OrcLib/CsvFileWriter.cpp:660
↓ 4 callersFunctionWriterSingleTest
tests/OrcLibTest/structured_output_test.cpp:47
↓ 4 callersMethodinner_elts
src/OrcLib/Buffer.h:768
↓ 4 callersMethodis_head
<summary> Checks to see if specified msg id is at the head of the queue. </summary> <param name="_MsgId"> Message id to check for. </param> <returns>
src/OrcLib/MessageQueue.h:109
↓ 4 callersMethodis_head
<summary> Checks to see if specified msg id is at the head of the queue. </summary> <param name="_MsgId"> Message id to check for. </param> <returns>
src/OrcLib/PriorityBuffer.h:164
↓ 4 callersMethodpeek
<summary> Return the item at the head of the queue, without dequeuing </summary> <returns> Returns a pointer to the message found at the head of the q
src/OrcLib/PriorityBuffer.h:138
↓ 4 callersFunctionread_single_column
#4: Read only a single column of the whole parquet file
tests/OrcParquetTest/parquet_output.cpp:182
↓ 4 callersMethodyr_compiler_set_callback
src/OrcLib/YaraStaticExtension.cpp:30
↓ 4 callersMethodyr_finalize
src/OrcLib/YaraStaticExtension.cpp:90
↓ 3 callersMethodAddContinuationAttribute
src/OrcLib/AttributeList.cpp:446
↓ 3 callersMethodAddHexDump
src/OrcLib/Text/Tree.h:164
↓ 3 callersMethodAddMatch
src/OrcLib/FileFind.h:75
↓ 3 callersMethodAddReadLength
src/OrcLib/FileFind.h:89
↓ 3 callersMethodAddStream
src/OrcCommand/UtilitiesMain.h:399
↓ 3 callersMethodAddWithoutEOL
src/OrcLib/Text/Tree.h:146
↓ 3 callersFunctionAlignToDword
src/OrcLib/FileFormat/PeVersionInfo.cpp:55
↓ 3 callersFunctionAllocatedCellSize
Byte size of an allocated registry cell. Cell sizes are stored as a negative int32 for allocated cells (positive means free); the cell size is the mag
src/OrcLib/RegistryWalker.cpp:33
↓ 3 callersMethodApplicationInfoOffset
src/OrcLib/Filesystem/Ntfs/ShadowCopy/CatalogEntry.h:122
↓ 3 callersFunctionBuildColumnFormat
Returns the format string for a non-string column, e.g. L",{:02X}" or L",{}". 'leadingDelimiter' is either the CSV delimiter or an empty string for th
src/OrcLib/CsvFileWriter.cpp:52
↓ 3 callersMethodCheckStream
src/OrcLib/FileInfo.cpp:601
↓ 3 callersMethodClose
src/OrcApacheOrcLib/ApacheOrcWriter.cpp:330
↓ 3 callersMethodClose
src/OrcLib/JournalingStream.cpp:252
↓ 3 callersMethodCommit
src/OrcCapsule/Utilities/Resource.cpp:311
↓ 3 callersMethodCompleteArchive
src/OrcCommand/Command/WolfLauncher/WolfExecution_Execute.cpp:866
↓ 3 callersMethodCompleteExecution
src/OrcCommand/Command/WolfLauncher/WolfExecution_Execute.cpp:803
↓ 3 callersMethodCompleteExecution
src/OrcLib/CommandExecute.cpp:553
↓ 3 callersMethodConfigure
src/OrcLib/OutputSpec.cpp:174
↓ 3 callersFunctionContainsBadChars
src/OrcCommand/Command/RegInfo/RegInfo_Run.cpp:148
↓ 3 callersFunctionConvertBase64
src/OrcLib/Convert.h:69
← previousnext →401–500 of 5,324, ranked by callers