{"repo":"saferwall/pe","free":true,"listed":false,"github":"https://github.com/saferwall/pe","clone":"git clone https://github.com/saferwall/pe.git","description":"A :zap: lightweight Go package to parse, analyze and extract metadata from Portable Executable (PE) binaries. Designed for malware analysis tasks and robust against PE malformations.","language":"Go","stars":395,"topics":["pe-file","portable-executable","malware","pe","coff","pe-malformations","malware-analysis","parsing","go","golang"],"license":"MIT","category":"security-tools","readme_excerpt":"Portable Executable Parser pe is a go package for parsing the portable executable file format. This package was designed with malware analysis in mind, and being resistent to PE malformations. Table of content - Portable Executable Parser - Table of content - Features - Installing - Using the library - PE Header - Rich Header - Iterating over sections - Roadmap - Fuzz Testing - Projects Using This Library - References Features - Works with PE32/PE32+ file format. - Supports Intel x86/AMD64/ARM7ARM7 Thumb/ARM8-64/IA64/CHPE architectures. - MS DOS header. - Rich Header (calculate checksum and hash). - NT Header (file header + optional header). - COFF symbol table and string table. - Sections headers + entropy calculation. - Data directories - Import Table + ImpHash calculation. - Export Table - Resource Table - Exceptions Table - Security Table + Authentihash calculation. - Relocations Table - Debug Table (CODEVIEW, POGO, VC FEATURE, REPRO, FPO, EXDLL CHARACTERISTICS debug types). - TLS Table - Load Config Directory (SEH, GFID, GIAT, Guard LongJumps, CHPE, Dynamic Value Reloc Table, Enclave Configuration, Volatile Metadata tables). - Bound Import Table - Delay Import Table - COM Table (CLR Metadata Header, Metadata Table Streams) - Report several anomalies Installing Using this go package is easy. First, use go get to install the latest version of the library. This command will install the pedumper executable along with the library and its dependencies: go get -u github.com/saf","default_branch":null,"files":null,"tree":[],"storefront":"/r/saferwall","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/saferwall/pe/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}