Skip to content

Glossary

Section table

The list of a PE file's sections — name, virtual address and size, raw offset and size, and permissions — used to map the file into memory.

Each 40-byte section header gives a name (up to 8 characters), the section's virtual address and size in memory, its offset and size in the file, and characteristics: code or data, readable, writable, executable. The loader maps each section to its virtual address; tools convert RVAs to file offsets through this table.

Typical compiler sections are .text, .rdata, .data, .pdata, .rsrc and .reloc. Unusual names, sections that are both writable and executable, and high entropy are classic packing signs — see detecting packed executables.