Glossary Forensics

Portable Executable (PE) file

The Portable Executable format is the structure of Windows programs and libraries (.exe, .dll, .sys), with headers followed by named sections.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

A file begins with the bytes MZ (4D 5A), and a pointer near the start leads to the signature PE\0\0 (50 45 00 00). Sections such as .text (code), .data and .rsrc (resources) each have a size and an entropy that analysts inspect. See the Executable Forensics.

Try these tools

See also

  • Glossary Import table
    The import table of an executable lists the library functions the program calls, such as Windows API functions.
  • Glossary Packer
    A packer compresses or encrypts an executable and adds a small stub that restores the original code in memory when the program runs.
  • Glossary Entropy
    In security, entropy measures how unpredictable something is, such as a password or key, usually expressed in bits.
AdSense Placeholder
Slot: footer_leaderboard