Skip to content

Series

Investigating PE files

3 posts in this series. Read them in order or jump to any one.

  1. Detecting Packed Executables: UPX, Entropy and Other Signs

    Static signs that a Windows executable is packed or protected — section names, entropy, W+X sections, entry point, imports, overlay — and their pitfalls.

  2. How to Collect Suspicious Executables Safely

    Find and copy suspicious EXE, DLL and SYS files from a Windows host or image without running them: PowerShell, Velociraptor, disk images and pitfalls.

  3. Analyze an EXE or DLL in Your Browser, Without Running It

    Step-by-step static triage of Windows executables with the free PE Parser: load files or a ZIP, read indicators, compare builds and export results.

All posts in this series

Static signs that a Windows executable is packed or protected — section names, entropy, W+X sections, entry point, imports, overlay — and their pitfalls.
Find and copy suspicious EXE, DLL and SYS files from a Windows host or image without running them: PowerShell, Velociraptor, disk images and pitfalls.
Step-by-step static triage of Windows executables with the free PE Parser: load files or a ZIP, read indicators, compare builds and export results.