A–Z
Glossary
Plain-language definitions of the PE format and static analysis terms used across the blog.
- Entropy (Shannon entropy)
- A measure, in bits per byte from 0 to 8, of how random data looks; values close to 8 indicate compressed or encrypted content.
- Overlay (appended data)
- Data stored in a PE file after the end of its last section, which the Windows loader does not map: installer payloads, archives, configuration, signatures.
- PDB path
- The path of the debug symbols file recorded in a PE file's CodeView debug record, often revealing the build machine's folders and user name.
- TLS callback
- A function listed in a PE file's thread-local-storage directory that Windows calls before the program's entry point and on thread start and exit.
- Authenticode
- Microsoft's code-signing format for PE files: a PKCS #7 signature over a hash of the file, stored in the certificate table.
- Imphash (import hash)
- An MD5 of a PE file's ordered import list, introduced by Mandiant in 2014 to group malware samples built from the same code.
- Rich header
- An undocumented, XOR-masked block written by Microsoft linkers into the DOS stub, listing the compiler and linker builds used to produce a PE file.
- Import table and IAT
- The PE structures that list the DLL functions a program needs; the loader resolves them and writes their addresses into the import address table (IAT).
- MZ header (MS-DOS header)
- The 64-byte header at the start of every PE file, beginning with the letters MZ, whose e_lfanew field points to the PE header.
- Optional header
- The PE header that tells the Windows loader how to map and start the image: PE32 or PE32+, entry point, image base, subsystem, checksum, flags and data directories.
- PE format (Portable Executable)
- The file format of Windows executables, DLLs, drivers and EFI binaries: an MS-DOS header, a PE signature, COFF and optional headers, and a section table.
- Section table
- The list of a PE file's sections — name, virtual address and size, raw offset and size, and permissions — used to map the file into memory.