Skip to content

PE Features

Each page explains one part of the PE format: what it is, why it matters for analysis, where to find it in the GUI, which CLI switch and JSON key expose it, and practical examples.

Structure Why you care CLI MCP
Headers & Sections Architecture, entry point, hardening flags, layout --headers --dirs --sections analyze_pe
Data directories, one page each:
0 · Export Exported functions, forwarders, DLL proxying --exports list_exports
1 · Import Capabilities and API usage, ImpHash --imports list_imports
2 · Resource Icons, version info, embedded payloads --resources analyze_pe
3 · Exception Function boundaries, unwind data --exception analyze_pe
4 · Security Authenticode: who signed it, was it modified --security check_signature
5 · Base Relocation ASLR support, rebase preview --basereloc analyze_pe
6 · Debug PDB path, build fingerprints --debug analyze_pe
7 · Architecture Reserved; non-zero is an anomaly --dirs analyze_pe
8 · Global Pointer GP register (MIPS/IA-64) --dirs analyze_pe
9 · TLS Code that runs before the entry point --tls analyze_pe
10 · Load Config CFG, SafeSEH, security cookie --loadconfig analyze_pe
11 · Bound Import Pre-resolved imports --bound-imports list_imports
12 · IAT Import address slots, unpacking --dirs, --imports list_imports
13 · Delay Import Imports loaded on first call --delay-imports list_imports
14 · COM Descriptor (.NET) Managed and mixed-mode assemblies --net analyze_pe
15 · Reserved Must be zero --dirs analyze_pe
Runtime analysis Build settings, dependencies, source paths and obfuscation in .NET, Go, Rust and NativeAOT files --analysis analyze_pe
Rich Header & Manifest Build toolchain fingerprint, UAC level --richheader --appmanifest analyze_pe
Hashes & Entropy Threat intel lookups, packing detection --hashes get_hashes
Strings URLs, registry keys, IOCs, anti-analysis keywords --strings get_strings
Similarity Engine "Have I seen this (or something like it) before?" --similarity check_similarity