Portable Executable (PE)
Definition
The binary file format used by Windows executables (.exe), dynamic-link libraries (.dll), and drivers (.sys). The PE header contains a structured metadata block including the import table, section table, compilation timestamp, and entry point address. Parsing the PE header is a foundational step in static Windows malware analysis.
- Applies to
- .exe, .dll and .sys Windows binaries
- Key header fields
- Import table, section table, timestamp, entry point
- Primary use
- Static Windows malware analysis
Common questions
Why is the PE header useful before running a suspicious file?+
The import table lists which Windows API functions the binary calls, which often hints at its capabilities, such as network access or process injection, without needing to execute it in a sandbox first.
Can the PE header's compilation timestamp be trusted?+
Not on its own. Malware authors routinely forge or zero out this field, so analysts treat it as a lead to corroborate against other evidence rather than a reliable fact by itself.
Related terms
- Cryptographic Hash
- A fixed-length digest produced from a file's bytes by an algorithm such as MD5 (128-bit), SHA-1 (160-bit), or SHA-256 (256-bit). Identical files...
- Disassembly
- The process of converting raw binary machine code back into human-readable assembly language instructions. Disassembly is always achievable from a binary, unlike...
- Import Address Table (IAT)
- A section of the PE header that lists every external DLL and the functions the executable calls from each. A malware sample's...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Packer / Packing
- A technique in which the original malware code is compressed or encrypted and wrapped in a stub loader that decompresses or decrypts...