Skip to content

Series

PE triage fundamentals

4 posts in this series. Read them in order or jump to any one.

  1. The PE File Format for Incident Responders

    What matters in a Windows PE file when you triage a suspicious EXE, DLL or driver: headers, sections, imports, resources, signature and overlay.

  2. Imphash, Rich Header Hash and TLSH: Grouping Samples

    How imphash, the Rich header hash and TLSH group related Windows executables, how each is computed, and where each one breaks down.

  3. Authenticode Signatures: What You Can Verify Offline

    How Authenticode signs a PE file, which checks can be done from the file alone, and why a valid signature is not the same as a trusted one.

  4. PE Timestamps: Compile Time, Debug Time and Signing Time

    Where a Windows executable stores its times, which ones can be trusted, how reproducible builds and timestomping show up, and how to use them.

All posts in this series

What matters in a Windows PE file when you triage a suspicious EXE, DLL or driver: headers, sections, imports, resources, signature and overlay.
How imphash, the Rich header hash and TLSH group related Windows executables, how each is computed, and where each one breaks down.
How Authenticode signs a PE file, which checks can be done from the file alone, and why a valid signature is not the same as a trusted one.
Where a Windows executable stores its times, which ones can be trusted, how reproducible builds and timestomping show up, and how to use them.