<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PE Parser — Blog</title>
    <link>https://www.peparser.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Tue, 29 Sep 2026 13:58:24 GMT</lastBuildDate>
    <atom:link href="https://www.peparser.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Analyze an EXE or DLL in Your Browser, Without Running It</title>
      <link>https://www.peparser.com/en/blog/analyze-exe-dll-in-browser</link>
      <guid isPermaLink="true">https://www.peparser.com/en/blog/analyze-exe-dll-in-browser</guid>
      <description>Step-by-step static triage of Windows executables with the free PE Parser: load files or a ZIP, read indicators, compare builds and export results.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Collect Suspicious Executables Safely</title>
      <link>https://www.peparser.com/en/blog/collect-suspicious-executables-safely</link>
      <guid isPermaLink="true">https://www.peparser.com/en/blog/collect-suspicious-executables-safely</guid>
      <description>Find and copy suspicious EXE, DLL and SYS files from a Windows host or image without running them: PowerShell, Velociraptor, disk images and pitfalls.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Detecting Packed Executables: UPX, Entropy and Other Signs</title>
      <link>https://www.peparser.com/en/blog/detect-packed-executables-upx-entropy</link>
      <guid isPermaLink="true">https://www.peparser.com/en/blog/detect-packed-executables-upx-entropy</guid>
      <description>Static signs that a Windows executable is packed or protected — section names, entropy, W+X sections, entry point, imports, overlay — and their pitfalls.</description>
      <author>Florian Amette</author>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PE Timestamps: Compile Time, Debug Time and Signing Time</title>
      <link>https://www.peparser.com/en/blog/pe-timestamps-compile-time-forensics</link>
      <guid isPermaLink="true">https://www.peparser.com/en/blog/pe-timestamps-compile-time-forensics</guid>
      <description>Where a Windows executable stores its times, which ones can be trusted, how reproducible builds and timestomping show up, and how to use them.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Authenticode Signatures: What You Can Verify Offline</title>
      <link>https://www.peparser.com/en/blog/authenticode-signature-verification-offline</link>
      <guid isPermaLink="true">https://www.peparser.com/en/blog/authenticode-signature-verification-offline</guid>
      <description>How Authenticode signs a PE file, which checks can be done from the file alone, and why a valid signature is not the same as a trusted one.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Imphash, Rich Header Hash and TLSH: Grouping Samples</title>
      <link>https://www.peparser.com/en/blog/imphash-rich-header-tlsh-malware-clustering</link>
      <guid isPermaLink="true">https://www.peparser.com/en/blog/imphash-rich-header-tlsh-malware-clustering</guid>
      <description>How imphash, the Rich header hash and TLSH group related Windows executables, how each is computed, and where each one breaks down.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The PE File Format for Incident Responders</title>
      <link>https://www.peparser.com/en/blog/pe-file-format-forensics-guide</link>
      <guid isPermaLink="true">https://www.peparser.com/en/blog/pe-file-format-forensics-guide</guid>
      <description>What matters in a Windows PE file when you triage a suspicious EXE, DLL or driver: headers, sections, imports, resources, signature and overlay.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>