PE Features¶
Each page explains one part of the PE format: what it is, why it matters for analysis, where to find it in the GUI, which CLI switch and JSON key expose it, and practical examples.
| Structure | Why you care | CLI | MCP |
|---|---|---|---|
| Headers & Sections | Architecture, entry point, hardening flags, layout | --headers --dirs --sections | analyze_pe |
| Data directories, one page each: | |||
| 0 · Export | Exported functions, forwarders, DLL proxying | --exports | list_exports |
| 1 · Import | Capabilities and API usage, ImpHash | --imports | list_imports |
| 2 · Resource | Icons, version info, embedded payloads | --resources | analyze_pe |
| 3 · Exception | Function boundaries, unwind data | --exception | analyze_pe |
| 4 · Security | Authenticode: who signed it, was it modified | --security | check_signature |
| 5 · Base Relocation | ASLR support, rebase preview | --basereloc | analyze_pe |
| 6 · Debug | PDB path, build fingerprints | --debug | analyze_pe |
| 7 · Architecture | Reserved; non-zero is an anomaly | --dirs | analyze_pe |
| 8 · Global Pointer | GP register (MIPS/IA-64) | --dirs | analyze_pe |
| 9 · TLS | Code that runs before the entry point | --tls | analyze_pe |
| 10 · Load Config | CFG, SafeSEH, security cookie | --loadconfig | analyze_pe |
| 11 · Bound Import | Pre-resolved imports | --bound-imports | list_imports |
| 12 · IAT | Import address slots, unpacking | --dirs, --imports | list_imports |
| 13 · Delay Import | Imports loaded on first call | --delay-imports | list_imports |
| 14 · COM Descriptor (.NET) | Managed and mixed-mode assemblies | --net | analyze_pe |
| 15 · Reserved | Must be zero | --dirs | analyze_pe |
| Runtime analysis | Build settings, dependencies, source paths and obfuscation in .NET, Go, Rust and NativeAOT files | --analysis | analyze_pe |
| Rich Header & Manifest | Build toolchain fingerprint, UAC level | --richheader --appmanifest | analyze_pe |
| Hashes & Entropy | Threat intel lookups, packing detection | --hashes | get_hashes |
| Strings | URLs, registry keys, IOCs, anti-analysis keywords | --strings | get_strings |
| Similarity Engine | "Have I seen this (or something like it) before?" | --similarity | check_similarity |