官术网_书友最值得收藏!

Binary analysis tools

Binary analysis tools are used to parse binary files and extract information about the file. An analyst would be able to identify which applications are able to read or execute the binary. File types are generally identified from their magic header bytes. These Magic Header bytes are usually located at the beginning of a file. For example, a Microsoft executable file, an EXE file, begin with the MZ header (MZ is believed to be the initials of Mark Zbikowski, a developer from Microsoft during the DOS days). Microsoft Office Word documents, on the other hand, have these first four bytes as their Magic Header: 


The hexadecimal bytes in the preceding screenshot read as DOCFILE Other information such as text string also give hints. The following screenshot shows information indicating that the program was most likely built using Window Forms:


主站蜘蛛池模板: 桦南县| 莱阳市| 柘荣县| 北票市| 新疆| 花莲市| 肇东市| 襄樊市| 兰坪| 郸城县| 安庆市| 镇远县| 赤城县| 广东省| 延川县| 恩平市| 阜平县| 高青县| 隆子县| 和林格尔县| 康定县| 湘潭县| 乐平市| 汾阳市| 林州市| 高青县| 普兰店市| 五峰| 苏尼特右旗| 祁门县| 阳山县| 铅山县| 英吉沙县| 兴宁市| 保康县| 平湖市| 汉阴县| 通河县| 蒙阴县| 正蓝旗| 延津县|