PE Section Header Analyzer
Analyze Portable Executable (PE) section headers to inspect section names, sizes, characteristics flags, and entropy. Automatically flags suspicious sections including RWX regions, non-standard names, and high-entropy (packed/encrypted) data. Upload any .exe, .dll, .sys, or .ocx file for instant analysis.
Why Use Our PE Section Header Analyzer?
Complete PE Header Parsing
The PE section analyzer parses DOS headers, COFF file headers, and every section header in your PE executable. Extract machine type, timestamp, characteristics flags, virtual sizes, raw data sizes, and virtual addresses from any .exe, .dll, .sys, or .ocx file — all in your browser with no server upload.
Automatic Suspicious Flag Detection
Every section is automatically checked against known security concerns: W+E (RWX) permissions are flagged as dangerous, non-standard section names are highlighted, writable code sections trigger warnings, and anomalously high entropy sections are marked for investigation.
Per-Section Entropy Analysis
The PE section analyzer computes Shannon entropy for each section independently. Low entropy sections (.text, .rdata) indicate normal code, while sections with entropy above 7.0 bits/byte suggest packing, encryption, or compression — common indicators of malware or obfuscation.
100% Private Browser-Based Analysis
All PE parsing, entropy calculation, and analysis happens entirely in your browser using JavaScript. Your binary files never leave your device. No account required, no tracking, no data stored. Export the full analysis report as JSON for your records.
Common Use Cases for the PE Section Analyzer
Malware & Packer Detection
Security analysts use PE section analysis to identify packed or obfuscated malware. Packed executables often show non-standard section names (UPX0, UPX1, .aspack), W+X permission flags, and uniformly high entropy across all sections. The PE section analyzer makes these patterns instantly visible.
Exploit Development & Reverse Engineering
Reverse engineers analyze PE section characteristics to understand memory layout, find code caves for shellcode injection, identify writable code sections for exploitation, and map the executable structure before deeper analysis with debuggers and disassemblers.
Binary File Validation & Integrity Checking
Verify that a PE file has well-formed section headers with expected characteristics. Detect corrupted or tampered headers, missing sections, unusual alignments, or mismatched virtual and raw sizes that could indicate file corruption or intentional manipulation.
Malware Analysis Education & Training
Students learning malware analysis and binary reverse engineering use PE section analysis to understand how executables are structured. The interactive visualizations show real PE files with entropy heatmaps and characteristics decoding.
Software Protection & Anti-Tamper Verification
Software developers and security engineers verify that their protection mechanisms are correctly applied. Check that packers, protectors, and obfuscators produce expected section characteristics with proper entropy profiles.
Digital Forensics & Incident Response
Forensic investigators analyze PE files during incident response to quickly triage suspicious executables. Section analysis provides rapid indicators of packing, injection, or modification without requiring full reverse engineering.
Understanding PE Section Header Analysis
What is a PE Section Header?
The Portable Executable (PE) format is the standard executable file format used by Windows for .exe, .dll, .sys, and other executable files. A PE file is divided into sections, each with a 40-byte section headerthat describes the section's name, virtual size, raw data size, memory address, andcharacteristics flags. These flags define memory permissions (read, write, execute), content type (code, initialized data, uninitialized data), and special attributes (discardable, shared). The PE section analyzer decodes every field in these headers and computes per-section entropy for security analysis.
How Our PE Section Analyzer Works
- Upload your PE file — select any .exe, .dll, .sys, .ocx, or .scr file. The parser reads the file as bytes directly in your browser using the FileReader API, with no data uploaded to any server.
- Parse PE headers:the analyzer locates the DOS header (MZ magic), reads e_lfanew to find the PE signature, parses the COFF file header (machine, sections, timestamp, characteristics), then iterates through every section header at 40-byte intervals. Each section's name, sizes, addresses, relocation pointers, and characteristics flags are decoded.
- Entropy computation and flagging:for each section with raw data, the analyzer computes Shannon entropy by counting byte frequency and evaluating -Σp(i)log₂(p(i)). Sections are checked against a rules engine: W+E permission combos, non-standard section names, abnormally high entropy, and writable code patterns trigger suspicious flags.
Key Characteristics Flags Explained
- IMAGE_SCN_MEM_EXECUTE (0x10000000): the section contains executable code. Normal for .text sections. When combined with WRITE, creates an RWX section that is highly suspicious and commonly seen in packed malware.
- IMAGE_SCN_MEM_WRITE (0x40000000): the section can be written to at runtime. Expected for .data and .bss sections. Suspicious when combined with EXECUTE or when found on code-named sections.
- IMAGE_SCN_CNT_CODE (0x00000020): the section contains executable instructions. Standard for .text sections. If a section has CODE but not EXECUTE, or EXECUTE but not CODE, it may indicate unusual section configuration.
- IMAGE_SCN_MEM_DISCARDABLE (0x02000000): the section can be discarded once loaded. Common for .reloc and .debug sections. Not typically seen on code or data sections. Indicates the section is only needed during initial loading.
Privacy, Security & Usage Notes
The PE section analyzer processes all files entirely in your browser using JavaScript. No data is ever uploaded to any server, stored in any database, or shared with any third party. There is no file size limit — the only constraint is your browser's available memory. For very large executables (over 100 MB), the parsing may take a moment but will complete without any server communication. Export the full analysis report as JSON for integration with other tools or to keep for your records. The analyzer supports both PE32 (32-bit) and PE32+ (64-bit) formats, including files produced by all major compilers (MSVC, GCC/MinGW, Clang, NASM, Go, Rust).
Related Tools
Frequently Asked Questions About PE Section Analysis
A PE (Portable Executable) section is a contiguous block of memory within a Windows executable file (.exe, .dll, .sys) that contains a specific type of data — code (.text), initialized data (.data), resources (.rsrc), import tables (.idata), export tables (.edata), or relocation data (.reloc). Each section has a 40-byte header that defines its name, virtual size, raw data size, memory address, and permission flags. Analyzing these headers reveals critical information about the executable structure, potential packing, memory permission anomalies, and security concerns.
The most common standard PE sections include: .text (executable code), .data (initialized global/static data), .rdata (read-only initialized data, import/export tables), .bss (uninitialized data), .idata (import address table), .edata (export tables), .rsrc (resources like icons, dialogs, version info), .reloc (base relocations), .tls (thread-local storage), .pdata (exception handling data, x64), and .debug (debugging information). Non-standard section names are often indicators of custom packers or protectors.
Several characteristics make a section suspicious: (1) W+E (Read+Write+Execute) permissions — also known as RWX, a major red flag common in packed malware; (2) Non-standard section names like .aspack, .UPX0, .nsp0, or random alphanumeric names that indicate third-party packers; (3) Abnormally high entropy (above 7.0 bits/byte) suggesting encrypted or compressed payloads; (4) Writable code sections where executable permissions are combined with write permissions outside expected data sections; (5) Unusual virtual-to-raw size ratios where the virtual size is much larger than raw data.
Entropy measures the randomness or unpredictability of data, ranging from 0 (completely predictable, all bytes identical) to 8 (completely random, all 256 byte values equally frequent). In PE analysis, normal code sections (.text) typically have entropy between 4.5 and 6.5 bits/byte. Sections with entropy above 7.0 strongly suggest packing, encryption, or compression. Packed executables often have all sections showing uniformly high entropy, while normal executables show varying entropy levels across different sections.
An RWX section has all three memory permissions: Read, Write, and Execute (IMAGE_SCN_MEM_READ | IMAGE_SCN_MEM_WRITE | IMAGE_SCN_MEM_EXECUTE = 0xE0000000). This combination allows code to write new instructions to memory and then execute them — a classic pattern for shellcode injection, runtime unpacking, and self-modifying code. Modern Windows security features (DEP, ACG) specifically prevent creating RWX memory, so finding an RWX section in a PE file is a strong indicator of packer or protector usage.
The PE section analyzer automatically flags sections with characteristics and entropy patterns consistent with packing. Common packer indicators include: UPX (sections named UPX0, UPX1 with high entropy in UPX1), ASPack (.aspack section with W+E permissions), MPRESS (sections with .MPRSS1, .MPRSS2), Themida (.themida section, very high entropy), VMProtect (.vmp0, .vmp1 sections), and Enigma (randomized section names). The analyzer also flags non-standard section names and RWX combinations that are hallmarks of custom packers.
The analyzer processes any file with a valid PE header. Common extensions include .exe (executables), .dll (dynamic link libraries), .sys (kernel drivers), .ocx (ActiveX controls), .scr (screen savers), .cpl (control panel items), .efi (EFI boot modules), and .mun (language-neutral resource files). Both PE32 (32-bit, machine type 0x014c) and PE32+ (64-bit, machine type 0x8664) formats are fully supported, including files from MSVC, GCC/MinGW, Clang, NASM, Go, Rust, and Delphi compilers.
Section characteristics are a 32-bit bitfield where each bit represents a specific attribute. The most important flags are in the high 16 bits: Execute (0x10000000), Read (0x20000000), and Write (0x40000000). The low 16 bits describe content type: CODE (0x00000020), INITIALIZED_DATA (0x00000040), and UNINITIALIZED_DATA (0x00000080). For example, a normal .text section typically has characteristics 0x60000020 (CODE + EXECUTE + READ), while a normal .data section has 0xC0000040 (INITIALIZED_DATA + READ + WRITE). A suspicious RWX section would have 0xE0000020 (CODE + EXECUTE + READ + WRITE).
Yes, completely. The PE section analyzer processes all files entirely in your browser using JavaScript. Your executable files never leave your device and are never sent to any server. No account is required, no data is stored, and no tracking occurs. You can safely analyze proprietary executables, sensitive binaries, or confidential software without any risk of data exposure. The export feature saves the analysis as JSON locally on your machine.