Skip to content

Walkthroughs

Each walkthrough takes one real sample and answers one question with PPEE, step by step, without running anything. They start with an At a glance box like this one:

At a glance

Sample
the file, with its SHA-256 or name
Question
what you want to know
You'll use
the PPEE features involved, linked to their reference pages

and the full case studies end with a Verdict. Screenshots are from the Windows GUI; every step that has a CLI equivalent shows it.

Case studies

End-to-end investigations, one page each.

  • A NativeAOT ransomware that forgot its key


    C# compiled to native code, invisible to .NET tools. Recover its method names, its shadow-copy and recovery commands, and a ransom note that admits there is no key.

    NativeAOT · Strings · Manifest · Debug

    Start

  • A DLL that is only a payload container


    Exports that are data, a 3.7 MB encrypted blob and masked keys. Follow DllMain as it decodes, drops, loads and deletes the next stage, then decode that stage yourself.

    Navigator · Exports · Code window · --decode

    Start

  • A validly signed dropper carrying a stealer


    SIGNED & VERIFIED with an EV certificate. What the signature does and doesn't tell you, and where the program it runs hides.

    Authenticode · Exports · Overlay

    Start

  • From a URL to its call site


    A shellcode loader whose import table looks ordinary. Find the APIs it resolves at run time, the C2 URL, and the one instruction that uses it.

    Code analysis · Strings · References · Debug

    Start

Short walkthroughs, by question

Shorter walkthroughs live on the reference page of the feature they use. They have the same At a glance box.

Is it packed or protected?

Walkthrough Sample Interface
Find the original entry point of a UPX-packed dropper 77549422….exe GUI + CLI
The same, with --disasm only 77549422….exe CLI
A hooked function in a protected crackme crackme-Section_name.exe CLI
A 64-bit file with no unwind data M-Dl-exeption-tls.exe CLI
Are these TLS callbacks a trick? ef431e36….dll GUI + CLI
An obfuscated .NET crackme, and the deep pass crackme GUI + CLI

What does it steal, and how does it send it?

Walkthrough Sample Interface
Triage a stealer in four clicks STEALERDLL.dll GUI
A browser-credential stealer, judged from its code STEALERDLL.dll CLI
A credential stealer's import profile STEALERDLL.dll CLI
What a stealer resolves at run time STEALERDLL.dll CLI
A Rust infostealer, read from its panic paths 42c6a158….exe GUI + CLI

What does it drop, download or unpack?

Walkthrough Sample Interface
A shellcode loader: the APIs it hides 86c6bd80….exe CLI
A shellcode loader, instruction by instruction 86c6bd80….exe CLI
A dropper's embedded executable 3c6b036f….exe CLI + MCP
What does the code load from its resources? 3c6b036f….exe CLI
A URL hidden with XOR 106710ac….exe GUI
A PyInstaller program: which script runs, what is bundled e21e0977….exe GUI + CLI

Where does it phone home, and who built it?

Walkthrough Sample Interface
A Merlin C2 agent's configuration, no execution needed merlin.dll CLI
An obfuscated NativeAOT DLL g4tj2aybt7y2xoq92p5e4y.dll CLI

Work through them with an assistant

Every walkthrough works over MCP too. Give the assistant the sample path and the walkthrough's Question; it uses the same PPEE data through tools such as triage_pe.