IAT Analyzer
Analyze PE files to extract imported DLLs, resolve function names, and detect suspicious imports with severity ratings. Supports both PE32 (32-bit) and PE32+ (64-bit) formats. Enter hex bytes, upload a file, or load an example. Private, fast, and no signup required.
Analyze PE files to extract imported DLLs, resolved function names, and detect suspicious imports. Supports both PE32 (32-bit) and PE32+ (64-bit) formats. Paste raw hex bytes or upload an .exe/.dll/.sys file.
Paste PE file hex bytes or upload an .exe/.dll file to analyze its Import Address Table. The tool will extract DLL dependencies, imported functions, and flag suspicious imports. All processing happens locally in your browser.
Why Use Our IAT Analyzer?
Complete PE Import Parsing
Parse the full PE structure from DOS header through optional header to the import directory. Extract every imported DLL and function with ordinal or name-based resolution. See the raw import descriptor entries, lookup tables, and hint/name table values in a clean hierarchical view.
Suspicious Import Detection
Automatically flag suspicious and dangerous function imports commonly associated with malware, packers, and security tools. Categories include process manipulation, network activity, code injection, keylogging, anti-debugging, file system evasion, and persistence mechanisms.
Multi-Method Input
Paste raw hex bytes of a PE file, upload a .exe/.dll/.sys file, or load from built-in examples. The parser handles both 32-bit (PE32) and 64-bit (PE32+) formats, validates the DOS magic (MZ) and PE signature, and gracefully reports parsing errors.
Signal Details & Exportable Results
View the full signal breakdown: imported DLLs with function counts, individual functions with ordinal/hint/name details, suspicious import warnings with severity levels, and IAT structural data like the number of import descriptors and total imported symbols. Copy the full report for documentation.
Common Use Cases for IAT Analyzer
Malware Analysis & Reverse Engineering
Security researchers use the IAT analyzer to quickly identify the capabilities of unknown PE binaries. A single scan reveals what Windows APIs a sample imports - VirtualAlloc and WriteProcessMemory suggest code injection, while URLDownloadToFile and WinExec indicate download-and-execute behavior.
Threat Hunting & Incident Response
SOC analysts can scan suspicious binaries for known malicious import patterns. The analyzer flags dangerous combinations like CreateRemoteThread + VirtualAllocEx (process injection), or RegSetValueEx + CreateService (persistence), helping triage potential threats faster.
Packer & Protector Detection
Many packers and protectors modify or obfuscate the IAT to prevent static analysis. The analyzer detects suspicious patterns like resolved imports only at runtime, missing IID structures, or import tables pointing to non-standard sections, giving clues about which packer was used.
Software Development Debugging
Developers debugging DLL loading issues can use the IAT analyzer to verify that all import dependencies are correctly declared. Identify missing DLL references, incorrect ordinal imports, or unexpected delay-loaded dependencies that cause runtime errors.
PE Structure Education
Students and researchers learning about the PE format can use the IAT analyzer to explore how Windows executables declare dependencies. Visualize the DOS header, PE signature, optional header, data directories, and import descriptors in a single interactive view.
Compatibility & Portability Analysis
Analyze which Windows APIs a binary imports to determine its minimum supported OS version, wow64 compatibility, and dependency on specific library versions. Useful for porting applications to Linux via Wine or analyzing cross-platform compatibility.
Understanding the Import Address Table
What is the Import Address Table (IAT)?
The Import Address Table (IAT) is a critical structure in the Portable Executable (PE) file format used by Windows executables, DLLs, and drivers. It tells the Windows loader which functions from which DLLs the executable needs at runtime. When a PE file is loaded, the Windows loader resolves each import by looking up the function address in the corresponding DLL and writing that address into the IAT. This mechanism allows executables to call Windows API functions without knowing their addresses at compile time. The IAT is stored as an array of IMAGE_THUNK_DATA structures, each pointing either to an IMAGE_IMPORT_BY_NAME structure (name import) or containing an ordinal value (ordinal import).
How the PE Import Directory Works
- DOS Header - Every PE file starts with an MZ DOS header (magic bytes 0x4D 0x5A). The
e_lfanewfield at offset 0x3C points to the PE signature. - PE Header & Optional Header - After the PE signature (0x50450000), the COFF file header and optional header describe the file layout. The optional header's data directory array contains an entry for the Import Directory (index 1).
- Import Descriptors - Each imported DLL has an IMAGE_IMPORT_DESCRIPTOR structure containing:
OriginalFirstThunk(RVA of import lookup table),Name(RVA of DLL name string), andFirstThunk(RVA of IAT - thunk table). - Thunk Tables & Name Resolution - Each thunk entry is either an ordinal import (high bit set, low 16 bits = ordinal number) or an RVA to an IMAGE_IMPORT_BY_NAME structure containing a hint (2 bytes) and a function name string.
Suspicious Import Categories & Signals
- Process Manipulation: OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, ReadProcessMemory - indicators of code injection or memory manipulation.
- Network Activity: InternetOpen, URLDownloadToFile, WinHttpOpen, socket, connect, send - suggests network communication or payload downloading.
- File System Evasion: SetFileAttributesA (HIDDEN), MoveFileEx (delayed delete), DeleteFileA, ReplaceFile - common in malware cleanup routines.
- Persistence & Execution: RegSetValueEx, CreateService, CreateProcess, WinExec, ShellExecute - indicators of autorun mechanisms or process creation.
- Anti-Debugging: IsDebuggerPresent, NtQueryInformationProcess, OutputDebugString, CheckRemoteDebuggerPresent - used to detect analysis environments.
- Keylogging & Input Capture: SetWindowsHookEx, GetAsyncKeyState, GetForegroundWindow, GetWindowText - suggests keystroke or window capture functionality.
Privacy & Security
This tool runs entirely in your browser using client-side JavaScript. Your PE files, hex input, and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All parsing - DOS header validation, PE signature verification, import directory walking, thunk table resolution, name table parsing, and suspicious import detection - executes locally on your device. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it completely safe for analyzing proprietary binaries, malware samples, or sensitive executables.
Frequently Asked Questions About IAT Analyzer
The IAT is a table inside every Windows PE file that lists all the functions the executable imports from external DLLs. When the program runs, the Windows loader uses this table to locate and connect to the required functions. Analyzing the IAT reveals what system APIs a binary depends on, which is crucial for understanding its capabilities, identifying potential malware behavior, and debugging dependency issues.
The analyzer reads the raw bytes of a PE file and walks the standard PE structure: it validates the DOS magic (MZ), reads e_lfanew to find the PE signature, parses the file header and optional header, locates the import directory from the data directory array, and iterates through each IMAGE_IMPORT_DESCRIPTOR. For each descriptor, it resolves the DLL name, walks the thunk tables (OriginalFirstThunk or FirstThunk), and resolves each function by name or ordinal from the hint/name table.
The analyzer flags imports based on function purpose and common malware usage patterns. For example, VirtualAllocEx + WriteProcessMemory + CreateRemoteThread is a classic process injection triad. InternetOpen + URLDownloadToFile suggests payload downloading. RegSetValueEx + CreateService indicates persistence via registry or service installation. The categorization draws from known malware tradecraft, reverse engineering literature, and security research on Windows API abuse patterns.
Yes, the analyzer supports both PE32 (32-bit) and PE32+ (64-bit) formats. It reads the Magic field in the optional header (0x10B for PE32, 0x20B for PE32+) and adjusts structure sizes accordingly. The import directory parsing, thunk table walking, and name resolution work identically for both formats, with only the RVA size differing between 32-bit and 64-bit entries.
You can paste raw hex bytes (with or without spaces), upload a PE file (.exe, .dll, .sys, .ocx) from your computer, or load one of the built-in example PE structures. The hex parser handles both continuous hex strings and space-separated byte pairs. For uploaded files, the tool reads the file as an ArrayBuffer and converts it to a byte array for analysis.
An ordinal import identifies a function by its numeric position in the DLL's export table rather than by name. Ordinal imports are slightly faster to resolve and are commonly used in older DLLs (like Windows 9x era) or by obfuscated code to hide which functions are being called. Malware sometimes uses ordinal imports as an anti-analysis technique because it makes static analysis slightly harder.
Absolutely. The IAT Analyzer runs entirely in your browser. Your PE files, hex input, and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All PE parsing, import resolution, and suspicious import detection executes locally on your device with no API calls, analytics tracking, cookies, or data collection of any kind.
Yes - 100% free with no signup, no account, and no usage limits. Analyze as many PE files as you need, as many times as you want. There are no premium tiers, hidden charges, or rate limits. The tool runs entirely in your browser - your data never leaves your device.