<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PE Parser — Blog</title>
    <link>https://www.peparser.com/de/blog</link>
    <description>Latest from Blog</description>
    <language>de</language>
    <lastBuildDate>Tue, 29 Sep 2026 15:20:35 GMT</lastBuildDate>
    <atom:link href="https://www.peparser.com/de/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>EXE oder DLL im Browser analysieren – ohne Ausführung</title>
      <link>https://www.peparser.com/de/blog/analyze-exe-dll-in-browser</link>
      <guid isPermaLink="true">https://www.peparser.com/de/blog/analyze-exe-dll-in-browser</guid>
      <description>Statische Triage von Windows-Executables mit dem kostenlosen PE Parser: Dateien oder ZIP laden, Indikatoren lesen, Builds vergleichen, exportieren.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Verdächtige Executables sicher sichern</title>
      <link>https://www.peparser.com/de/blog/collect-suspicious-executables-safely</link>
      <guid isPermaLink="true">https://www.peparser.com/de/blog/collect-suspicious-executables-safely</guid>
      <description>Verdächtige EXE-, DLL- und SYS-Dateien von einem Windows-Host oder Image finden und kopieren, ohne sie auszuführen: PowerShell, Velociraptor, Images.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Gepackte Executables erkennen: UPX, Entropie und mehr</title>
      <link>https://www.peparser.com/de/blog/detect-packed-executables-upx-entropy</link>
      <guid isPermaLink="true">https://www.peparser.com/de/blog/detect-packed-executables-upx-entropy</guid>
      <description>Statische Hinweise auf gepackte Windows-Executables – Section-Namen, Entropie, W+X, Entry Point, Importe, Overlay – und ihre Fallstricke.</description>
      <author>Florian Amette</author>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PE-Zeitstempel: Kompilier-, Debug- und Signaturzeit</title>
      <link>https://www.peparser.com/de/blog/pe-timestamps-compile-time-forensics</link>
      <guid isPermaLink="true">https://www.peparser.com/de/blog/pe-timestamps-compile-time-forensics</guid>
      <description>Wo eine Windows-Executable ihre Zeiten speichert, welchen man trauen kann, wie sich Reproducible Builds und Timestomping zeigen – und wie man sie nutzt.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Authenticode-Signaturen: Was sich offline prüfen lässt</title>
      <link>https://www.peparser.com/de/blog/authenticode-signature-verification-offline</link>
      <guid isPermaLink="true">https://www.peparser.com/de/blog/authenticode-signature-verification-offline</guid>
      <description>Wie Authenticode eine PE-Datei signiert, welche Prüfungen allein mit der Datei möglich sind und warum gültig nicht gleich vertrauenswürdig ist.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Imphash, Rich-Header-Hash und TLSH: Samples gruppieren</title>
      <link>https://www.peparser.com/de/blog/imphash-rich-header-tlsh-malware-clustering</link>
      <guid isPermaLink="true">https://www.peparser.com/de/blog/imphash-rich-header-tlsh-malware-clustering</guid>
      <description>Wie Imphash, Rich-Header-Hash und TLSH verwandte Windows-Executables gruppieren, wie sie berechnet werden und wo jedes Verfahren an Grenzen stößt.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Das PE-Dateiformat für Incident Responder</title>
      <link>https://www.peparser.com/de/blog/pe-file-format-forensics-guide</link>
      <guid isPermaLink="true">https://www.peparser.com/de/blog/pe-file-format-forensics-guide</guid>
      <description>Was bei der Triage einer verdächtigen EXE, DLL oder eines Treibers zählt: Header, Sections, Importe, Ressourcen, Signatur und Overlay.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>