How to Collect Suspicious Executables Safely
Find and copy suspicious EXE, DLL and SYS files from a Windows host or image without running them: PowerShell, Velociraptor, disk images and pitfalls.
TL;DR. Start from execution evidence to know which binaries matter, copy them with their paths (copying never runs them), keep antivirus from eating them, and analyse copies only. The PE Parser accepts the result — loose files, a folder or a ZIP — as-is.
Step 1: Pivot from execution evidence
A disk holds tens of thousands of executables. Artefacts tell you which ones matter: Prefetch and Amcache name programs that ran, ShimCache and BAM add paths and times, and services, scheduled tasks and Run keys name what persists. User-writable folders — C:\ProgramData, %AppData%, %Temp%, Downloads, C:\Users\Public — are where dropped tools usually sit. In the fictional FIN-WKS-07 case used by our samples, that points to C:\ProgramData\Intel\m64.exe and the tools folder in svc_backup's Downloads.
Step 2: Copy them without running them
Reading a file does not execute it. On a live system, from Windows PowerShell run as administrator, this copies executables written in the last 14 days under the usual roots, keeping their paths:
$dst = 'C:\triage\pe'
$roots = 'C:\ProgramData', 'C:\Users', 'C:\Windows\Temp'
Get-ChildItem -Path $roots -Recurse -Force -File -Include *.exe, *.dll, *.sys, *.scr, *.cpl, *.ocx -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-14) -and $_.Length -lt 200MB } |
ForEach-Object {
$to = Join-Path $dst $_.FullName.Substring(3)
New-Item -ItemType Directory -Force -Path (Split-Path $to) | Out-Null
Copy-Item -LiteralPath $_.FullName -Destination $to -Force
}
Adjust the roots and days. Last-write times can be forged, so also copy the exact paths found in step 1.
Velociraptor collects the binaries behind running processes, services, scheduled tasks, Prefetch entries and shortcut targets with the _Live group of Windows.Triage.Targets (Velociraptor triage artifacts). By default it skips signed executables (CollectionPolicy=ExcludeSigned):
velociraptor.exe artifacts collect Windows.Triage.Targets --args HighLevelTargets=[\"_Live\"] --output C:\triage\pe.zip
To collect by path pattern instead, Windows.Search.FileFinder with SearchFilesGlob and Upload_File=Y uploads every match.
KAPE targets collect artefacts (registry, logs, Prefetch), not arbitrary binaries; use it for the step-1 evidence and one of the methods above for the files.
From a disk image mounted read-only as E:, robocopy copies by extension and age while keeping the tree:
robocopy E:\ProgramData C:\triage\pe\ProgramData *.exe *.dll *.sys *.scr /S /XJ /B /R:0 /W:0 /NP /NDL /MAXAGE:30
Check the image's volume shadow copies too: a binary deleted after the attack may still be there.
Step 3: Protect the copies
- Antivirus may delete or quarantine the samples as you copy them. Add an exclusion for the destination or work from an image.
- Hash everything before analysis and record the source paths.
- Pack with the
tar.exebuilt into Windows 10 1803 and later:tar -a -c -f C:\triage\pe.zip -C C:\triage pe. Password-protected ZIPs are the norm for sharing samples, but the browser cannot open them: extract before dropping.
Step 4: Analyse statically
Drop the folder or ZIP onto the PE Parser. Files are recognised by their MZ header, so renamed payloads are found; unrelated files are counted and ignored. The batch table groups builds by imphash, and each file gets hashes, signature checks and indicators. Then read the PE format guide for what each view means.
FAQ
Is it safe to copy a running malware executable?
Copying reads the file; it does not execute it. Never open or double-click the copy, keep it on an analysis system, and expect antivirus to quarantine it unless the destination is excluded.
Does KAPE collect executables?
KAPE targets are designed to collect forensic artefacts such as registry hives, logs and Prefetch, not arbitrary binaries. Use a scripted copy, Velociraptor, or point KAPE at a specific folder you already identified.