Talk With an Expert

PE Parsing with WinDbg

PE Parsing with WinDbg (PDF, 0.62MB)Published: 19 Dec, 2024
Created by:
SANS Institute
SANS Institute

This reference provides essential WinDbg commands to manually parse PE (Portable Executable) images and explore key system structures. By mastering these manual PE parsing techniques in WinDbg, analysts gain a deeper understanding of the PE format and lays the groundwork for automating PE parsing and analysis programmatically using languages like C++, enabling the creation of powerful custom tools and workflows, topics covered in SEC670: Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Control.

Author

SANS Institute
SANS Institute

SANS Institute

Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cyber security professionals with the practical skills and knowledge they need to make our world a safer place.

Read more about SANS Institute