Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: PE Section Name Descriptions - SANS Internet Storm Center SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
PE Section Name Descriptions

PE files (.exe, .dll, ...) have sections: a section with code, one with data, ... Each section has a name, and different compilers use different section names. Section names can help us identify the compiler and the type of PE file we are analyzing.

@Hexacorn compiled a list of section names with corresponding description, you can find the latest version here. I find this list so useful, that I included it (with permission) in my pecheck.py tool. pecheck is a Python tool to analyze PE files, based on Ero Carrera's pefile module. Use -o s (overview of sections) to see the sections, with name, size, entropy and description:

Didier Stevens
Microsoft MVP
blog.DidierStevens.com DidierStevensLabs.com

DidierStevens

180 Posts
ISC Handler
Congrats on the Microsoft MVP!
Anonymous

Posts
Thanks!
DidierStevens

180 Posts Posts
ISC Handler

Sign Up for Free or Log In to start participating in the conversation!