官术网_书友最值得收藏!

Examining the PE header

Portable executable (PE) files are a common Windows file type. PE files include the .exe, .dll, and .sys files. All PE files are distinguished by having a PE header, which is a header section of the code that instructs Windows on how to parse the subsequent code. The fields from the PE header are often used as features in the detection of malware. To easily extract the multitude of values of the PE header, we will utilize the pefile Python module. In this recipe, we will parse the PE header of a file, and then print out notable portions of it.

主站蜘蛛池模板: 龙口市| 汉川市| 陇西县| 新泰市| 崇州市| 江达县| 大新县| 奉节县| 仪征市| 丽水市| 盘锦市| 彭水| 台北县| 南充市| 长垣县| 繁昌县| 哈尔滨市| 读书| 蓬溪县| 广河县| 云霄县| 五台县| 镇原县| 正安县| 安吉县| 乌鲁木齐县| 长海县| 南丹县| 常熟市| 青海省| 漯河市| 麻栗坡县| 旌德县| 绥江县| 阜新市| 阳西县| 阳朔县| 伊吾县| 饶平县| 琼海市| 石河子市|