官术网_书友最值得收藏!

Examining the PE header

Portable executable (PE) files are a common Windows file type. PE files include the .exe, .dll, and .sys files. All PE files are distinguished by having a PE header, which is a header section of the code that instructs Windows on how to parse the subsequent code. The fields from the PE header are often used as features in the detection of malware. To easily extract the multitude of values of the PE header, we will utilize the pefile Python module. In this recipe, we will parse the PE header of a file, and then print out notable portions of it.

主站蜘蛛池模板: 平顺县| 康定县| 洪湖市| 固安县| 彰化县| 屏东市| 襄垣县| 仁怀市| 临朐县| 长武县| 兴业县| 河西区| 漯河市| 马边| 奉贤区| 芦溪县| 九寨沟县| 斗六市| 门源| 陇南市| 栾川县| 安多县| 阳高县| 门头沟区| 囊谦县| 海丰县| 祁东县| 遵义市| 上杭县| 河曲县| 遂平县| 岚皋县| 伊春市| 资源县| 定结县| 济阳县| 大新县| 双城市| 屏山县| 凤冈县| 蒲江县|