PE Anatomist – Explore data structures in portable executable files
rammerlabs.alidml.ru
rammerlabs.alidml.ru
Is it being open-source the USP?
The way a PE file is defined is interesting. They managed to cram a completely different file format into the DOS 'MZ' format. Including the NE and LE formats. I think the NE one had a bunch of sub targets (OS/2, win32s, etc).
https://wiki.osdev.org/PE https://wiki.osdev.org/NE
It is quite the nesting doll of executable formats. If I remember correctly PE also holds .NET in some way as another sub format.
(sigh at how acronyms are the source for endless insider snark.)
this seems kind of strange. does MIT lic. permit that the source code be withheld?
I'm guessing if the product is popular they want to have the ability to monetize it in the future.
Sad that this tool also is not open source but better then nothing. So Thanks to the author!
Ghidra probably the most powerful. The PE structures are public, every compiler, binutil or decompiler has it.
In my experience, messing with PE files is useful in a few areas:
- Compiler Development (PE files tell Windows how to load your code into memory, what resources they need/provide, and how to execute your code, etc)
- Reverse Engineering (Extracting the above info, plus locating executable files in memory and dumping them back to disk if they're e.g. packed)
- Game Cheating/Malware (You can simulate the PE loading process to turn e.g. a DLL into what basically amounts to shellcode, allowing you to skip putting your stuff on disk, to make your payloads harder to locate in memory, and to write custom obfuscation as part of the loading process)
There might be more uses I'm not thinking of, but those are the three I have experience with. It's a handy bit of trivia to know if you like dicking around w/ systems-level stuff in Windows for sure.Probably doesn't need to be said, but just in case PE is how Windows formats .exe, .dll, .sys, etc executable files.
It's basically the counterpart of ELF (Executable and Linkable Format) files, but on Windows.
Yes, it's guaranteed to have been backdoored by the NSA.
[0]: https://www.virustotal.com/gui/url/826fca3edb8d883bb9710cabb...