Glossary Forensics

Import table

The import table of an executable lists the library functions the program calls, such as Windows API functions.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

It shows capabilities without running the file: imports for networking, process injection or registry access hint at behaviour. A very small table can mean the file is packed and resolves imports at run time.

Try these tools

See also

  • Glossary Portable Executable (PE) file
    The Portable Executable format is the structure of Windows programs and libraries (.exe, .dll, .sys).
  • Glossary Packer
    A packer compresses or encrypts an executable and adds a small stub that restores the original code in memory when the program runs.
  • Glossary Malware
    Malware is any software designed to harm a device or steal from its user, including viruses, worms, ransomware, spyware and trojans.
AdSense Placeholder
Slot: footer_leaderboard