Skip to content

Glossary

TLS callback

A function listed in a PE file's thread-local-storage directory that Windows calls before the program's entry point and on thread start and exit.

The TLS directory lets a program initialise thread-local data. Its AddressOfCallBacks field points to a null-terminated list of functions that the loader calls when the process and each thread start and stop — before the entry point runs.

Some runtimes use TLS callbacks legitimately. Malware and protectors use them to run code before a debugger breaks on the entry point, for anti-debugging or unpacking. Their presence is worth a look, not a verdict; see the PE format guide.