Posts tagged: #dfir
Step-by-step static triage of Windows executables with the free PE Parser: load files or a ZIP, read indicators, compare builds and export results.
Find and copy suspicious EXE, DLL and SYS files from a Windows host or image without running them: PowerShell, Velociraptor, disk images and pitfalls.
What matters in a Windows PE file when you triage a suspicious EXE, DLL or driver: headers, sections, imports, resources, signature and overlay.