Skip to content

Blog

Guides to Windows PE files for incident responders: headers, imports, signatures, packers and triage.

Step-by-step static triage of Windows executables with the free PE Parser: load files or a ZIP, read indicators, compare builds and export results.
Find and copy suspicious EXE, DLL and SYS files from a Windows host or image without running them: PowerShell, Velociraptor, disk images and pitfalls.
Static signs that a Windows executable is packed or protected — section names, entropy, W+X sections, entry point, imports, overlay — and their pitfalls.
Where a Windows executable stores its times, which ones can be trusted, how reproducible builds and timestomping show up, and how to use them.
How Authenticode signs a PE file, which checks can be done from the file alone, and why a valid signature is not the same as a trusted one.
How imphash, the Rich header hash and TLSH group related Windows executables, how each is computed, and where each one breaks down.
What matters in a Windows PE file when you triage a suspicious EXE, DLL or driver: headers, sections, imports, resources, signature and overlay.