Skip to content

Portable Executable (PE)

Definition

The binary file format used by Windows executables (.exe), dynamic-link libraries (.dll), and drivers (.sys). The PE header contains a structured metadata block including the import table, section table, compilation timestamp, and entry point address. Parsing the PE header is a foundational step in static Windows malware analysis.

Applies to
.exe, .dll and .sys Windows binaries
Key header fields
Import table, section table, timestamp, entry point
Primary use
Static Windows malware analysis

Common questions

Why is the PE header useful before running a suspicious file?+

The import table lists which Windows API functions the binary calls, which often hints at its capabilities, such as network access or process injection, without needing to execute it in a sandbox first.

Can the PE header's compilation timestamp be trusted?+

Not on its own. Malware authors routinely forge or zero out this field, so analysts treat it as a lead to corroborate against other evidence rather than a reliable fact by itself.

Related terms

Cryptographic Hash
A fixed-length digest produced from a file's bytes by an algorithm such as MD5 (128-bit), SHA-1 (160-bit), or SHA-256 (256-bit). Identical files...
Disassembly
The process of converting raw binary machine code back into human-readable assembly language instructions. Disassembly is always achievable from a binary, unlike...
Import Address Table (IAT)
A section of the PE header that lists every external DLL and the functions the executable calls from each. A malware sample's...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
Packer / Packing
A technique in which the original malware code is compressed or encrypted and wrapped in a stub loader that decompresses or decrypts...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.