{"id":13468481,"url":"https://github.com/erocarrera/pefile","last_synced_at":"2026-08-27T20:45:25.828Z","repository":{"id":30318745,"uuid":"33870982","full_name":"erocarrera/pefile","owner":"erocarrera","description":"pefile is a Python module to read and work with PE (Portable Executable) files","archived":false,"fork":false,"pushed_at":"2026-08-21T22:29:03.000Z","size":1269225,"stargazers_count":2064,"open_issues_count":62,"forks_count":541,"subscribers_count":72,"default_branch":"master","last_synced_at":"2026-08-22T08:24:24.236Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/erocarrera.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":"CITATION.cff","codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null,"disclosure":null}},"created_at":"2015-04-13T13:45:19.000Z","updated_at":"2026-08-22T02:59:49.000Z","dependencies_parsed_at":"2025-04-11T21:07:54.981Z","dependency_job_id":"5ea013df-54dc-4ac9-ab3e-83b71a45abbe","html_url":"https://github.com/erocarrera/pefile","commit_stats":{"total_commits":499,"total_committers":81,"mean_commits":6.160493827160494,"dds":"0.47294589178356716","last_synced_commit":"80535f51f024805066c6ccfa062cd21d1a7afba5"},"previous_names":[],"tags_count":36,"template":false,"template_full_name":null,"purl":"pkg:github/erocarrera/pefile","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/erocarrera%2Fpefile","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/erocarrera%2Fpefile/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/erocarrera%2Fpefile/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/erocarrera%2Fpefile/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/erocarrera","download_url":"https://codeload.github.com/erocarrera/pefile/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/erocarrera%2Fpefile/sbom","scorecard":{"id":381643,"data":{"date":"2025-08-12T07:28:39Z","repo":{"name":"github.com/erocarrera/pefile","commit":"4b3b1e2e568a88d4f1897d694d684f23d9e270c4"},"scorecard":{"version":"v4.13.1","commit":"49c0eed3a423f00c872b5c3c9f1bbca9e8aae799"},"score":4.2,"checks":[{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#binary-artifacts"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#branch-protection"}},{"name":"CI-Tests","score":5,"reason":"8 out of 14 merged PRs checked by a CI test -- score normalized to 5","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#ci-tests"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#cii-best-practices"}},{"name":"Code-Review","score":5,"reason":"found 11 unreviewed changesets out of 25 -- score normalized to 5","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#code-review"}},{"name":"Contributors","score":10,"reason":"10 different organizations found -- score normalized to 10","details":["Info: contributors work for ForensicArtifacts,OpenRCE,StratumAuhuur,The-Fortress-of-Brolitude,google,libyal,log2timeline,py4n6,pydot,stratum0"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#contributors"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#dangerous-workflow"}},{"name":"Dependency-Update-Tool","score":0,"reason":"no update tool detected","details":["Warn: tool 'RenovateBot' is not used: Follow the instructions from https://docs.renovatebot.com/configuration-options/. (Low effort)","Warn: tool 'Dependabot' is not used: Follow the instructions from https://docs.github.com/code-security/dependabot/dependabot-version-updates/about-dependabot-version-updates. (Low effort)","Warn: tool 'PyUp' is not used: Follow the instructions from https://docs.pyup.io/docs. (Low effort)","Warn: tool 'Sonatype Lift' is not used: Follow the instructions from https://help.sonatype.com/lift/getting-started. (Low effort)"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#dependency-update-tool"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no OSSFuzz integration found: Follow the steps in https://github.com/google/oss-fuzz to integrate fuzzing for your project.\nOver time, try to add fuzzing for more functionalities of your project. (High effort)","Warn: no OneFuzz integration found: Follow the steps in https://github.com/microsoft/onefuzz to start fuzzing for your project.\nOver time, try to add fuzzing for more functionalities of your project. (High effort)","Warn: no GoBuiltInFuzzer integration found: Follow the steps in https://go.dev/doc/fuzz/ to enable fuzzing on your project.\nOver time, try to add fuzzing for more functionalities of your project. (Medium effort)","Warn: no PythonAtherisFuzzer integration found: Follow the steps in https://github.com/google/atheris to enable fuzzing on your project.\nOver time, try to add fuzzing for more functionalities of your project. (Medium effort)","Warn: no CLibFuzzer integration found: Follow the steps in https://llvm.org/docs/LibFuzzer.html to enable fuzzing on your project.\nOver time, try to add fuzzing for more functionalities of your project. (Medium effort)","Warn: no CppLibFuzzer integration found: Follow the steps in https://llvm.org/docs/LibFuzzer.html to enable fuzzing on your project.\nOver time, try to add fuzzing for more functionalities of your project. (Medium effort)","Warn: no SwiftLibFuzzer integration found: Follow the steps in https://google.github.io/oss-fuzz/getting-started/new-project-guide/swift-lang/ to enable fuzzing on your project.\nOver time, try to add fuzzing for more functionalities of your project. (Medium effort)","Warn: no RustCargoFuzzer integration found: Follow the steps in https://rust-fuzz.github.io/book/cargo-fuzz.html to enable fuzzing on your project.\nOver time, try to add fuzzing for more functionalities of your project. (Medium effort)","Warn: no JavaJazzerFuzzer integration found: Follow the steps in https://github.com/CodeIntelligenceTesting/jazzer to enable fuzzing on your project.\nOver time, try to add fuzzing for more functionalities of your project. (Medium effort)","Warn: no ClusterFuzzLite integration found: Follow the steps in https://github.com/google/clusterfuzzlite to integrate fuzzing as part of CI.\nOver time, try to add fuzzing for more functionalities of your project. (High effort)","Warn: no HaskellPropertyBasedTesting integration found: Use one of the following frameworks to fuzz your project:\nQuickCheck: https://hackage.haskell.org/package/QuickCheck\nhedgehog: https://hedgehog.qa/\nvalidity: https://github.com/NorfairKing/validity\nsmallcheck: https://hackage.haskell.org/package/smallcheck\nhspec: https://hspec.github.io/\ntasty: https://hackage.haskell.org/package/tasty (High effort)","Warn: no TypeScriptPropertyBasedTesting integration found: Use fast-check: https://github.com/dubzzz/fast-check (High effort)","Warn: no JavaScriptPropertyBasedTesting integration found: Use fast-check: https://github.com/dubzzz/fast-check (High effort)"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: License file found in expected location: LICENSE:1","Info: FSF or OSI recognized license: LICENSE:1"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#license"}},{"name":"Maintained","score":0,"reason":"0 commit(s) out of 30 and 0 issue activity out of 30 found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"no published package detected","details":["Warn: no GitHub/GitLab publishing workflow detected"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":6,"reason":"dependency not pinned by hash detected -- score normalized to 6","details":["Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yaml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/erocarrera/pefile/tests.yaml/master?enable=pin","Warn: pipCommand not pinned by hash: .github/workflows/tests.yaml:88","Warn: pipCommand not pinned by hash: .github/workflows/tests.yaml:89","Warn: pipCommand not pinned by hash: .github/workflows/tests.yaml:42","Warn: pipCommand not pinned by hash: .github/workflows/tests.yaml:43","Info:  16 out of  16 GitHub-owned GitHubAction dependencies pinned","Info:   6 out of   7 third-party GitHubAction dependencies pinned","Info:   0 out of   4 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":8,"reason":"SAST tool detected but not run on all commits","details":["Warn: 13 commits out of 19 are checked with a SAST tool","Info: SAST tool detected: CodeQL"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#sast"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected: On GitHub:\nEnable private vulnerability disclosure in your repository settings https://docs.github.com/en/code-security/security-advisories/repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository\nAdd a section in your SECURITY.md indicating you have enabled private reporting, and tell them to follow the steps in https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability to report vulnerabilities.\nOn GitLab:\nAdd a section in your SECURITY.md indicating the process to disclose vulnerabilities for your project.\nExamples: https://github.com/ossf/scorecard/blob/main/SECURITY.md, https://github.com/slsa-framework/slsa-github-generator/blob/main/SECURITY.md, https://github.com/sigstore/.github/blob/main/SECURITY.md.\nFor additional information on vulnerability disclosure, see https://github.com/ossf/oss-vulnerability-guide/blob/main/maintainer-guide.md. (Medium effort)","Warn: no security file to analyze: On GitHub:\nEnable private vulnerability disclosure in your repository settings https://docs.github.com/en/code-security/security-advisories/repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository\nAdd a section in your SECURITY.md indicating you have enabled private reporting, and tell them to follow the steps in https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability to report vulnerabilities.\nOn GitLab:\nProvide a point of contact in your SECURITY.md.\nExamples: https://github.com/ossf/scorecard/blob/main/SECURITY.md, https://github.com/slsa-framework/slsa-github-generator/blob/main/SECURITY.md, https://github.com/sigstore/.github/blob/main/SECURITY.md. (Low effort)","Warn: no security file to analyze: On GitHub:\nEnable private vulnerability disclosure in your repository settings https://docs.github.com/en/code-security/security-advisories/repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository\nAdd a section in your SECURITY.md indicating you have enabled private reporting, and tell them to follow the steps in https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability to report vulnerabilities.\nOn GitLab:\nAdd a section in your SECURITY.md indicating the process to disclose vulnerabilities for your project.\nExamples: https://github.com/ossf/scorecard/blob/main/SECURITY.md, https://github.com/slsa-framework/slsa-github-generator/blob/main/SECURITY.md, https://github.com/sigstore/.github/blob/main/SECURITY.md. (Low effort)","Warn: no security file to analyze: On GitHub:\nEnable private vulnerability disclosure in your repository settings https://docs.github.com/en/code-security/security-advisories/repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository\nAdd a section in your SECURITY.md indicating you have enabled private reporting, and tell them to follow the steps in https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability to report vulnerabilities.\nOn GitLab:\nAdd a section in your SECURITY.md indicating the process to disclose vulnerabilities for your project.\nExamples: https://github.com/ossf/scorecard/blob/main/SECURITY.md, https://github.com/slsa-framework/slsa-github-generator/blob/main/SECURITY.md, https://github.com/sigstore/.github/blob/main/SECURITY.md. (Low effort)"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#security-policy"}},{"name":"Signed-Releases","score":0,"reason":"0 out of 5 artifacts are signed or have provenance","details":["Warn: release artifact v2024.8.26 does not have provenance: https://api.github.com/repos/erocarrera/pefile/releases/172024083","Warn: release artifact v2024.8.26 not signed: https://api.github.com/repos/erocarrera/pefile/releases/172024083","Warn: release artifact v2023.2.7 does not have provenance: https://api.github.com/repos/erocarrera/pefile/releases/91592882","Warn: release artifact v2023.2.7 not signed: https://api.github.com/repos/erocarrera/pefile/releases/91592882","Warn: release artifact v2022.5.30 does not have provenance: https://api.github.com/repos/erocarrera/pefile/releases/68165051","Warn: release artifact v2022.5.30 not signed: https://api.github.com/repos/erocarrera/pefile/releases/68165051","Warn: release artifact v2021.9.3 does not have provenance: https://api.github.com/repos/erocarrera/pefile/releases/48967171","Warn: release artifact v2021.9.3 not signed: https://api.github.com/repos/erocarrera/pefile/releases/48967171","Warn: release artifact v2021.9.2 does not have provenance: https://api.github.com/repos/erocarrera/pefile/releases/48910920","Warn: release artifact v2021.9.2 not signed: https://api.github.com/repos/erocarrera/pefile/releases/48910920"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#signed-releases"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:24","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:31","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:32","Info: topLevel 'contents' permission set to 'read': .github/workflows/dependency-review.yml:13","Info: topLevel permissions set to 'read-all': .github/workflows/scorecards.yml:18","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecards.yml:29","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecards.yml:30","Warn: no topLevel permission defined: .github/workflows/tests.yaml:1: Visit https://app.stepsecurity.io/secureworkflow/erocarrera/pefile/tests.yaml/master?enable=permissions\nTick the 'Restrict permissions for GITHUB_TOKEN'\nUntick other options\nNOTE: If you want to resolve multiple issues at once, you can visit https://app.stepsecurity.io/securerepo instead. (Low effort)","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#token-permissions"}},{"name":"Vulnerabilities","score":10,"reason":"no vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/49c0eed3a423f00c872b5c3c9f1bbca9e8aae799/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T15:35:23.229Z","repository_id":30318745,"created_at":"2025-08-18T15:35:23.229Z","updated_at":"2025-08-18T15:35:23.229Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36821667,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-22T02:00:06.114Z","response_time":51,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-31T15:01:11.876Z","updated_at":"2026-08-27T20:45:25.821Z","avatar_url":"https://github.com/erocarrera.png","language":"Python","funding_links":[],"categories":["Python",":wrench: Tools","Scripting","\u003ca id=\"620af0d32e6ac1f4a3e97385d4d3efc0\"\u003e\u003c/a\u003ePE","Reversing"],"sub_categories":["Before 2000","\u003ca id=\"574db8bbaafbee72eeb30e28e2799458\"\u003e\u003c/a\u003e工具"],"readme":"# pefile\n\n[![PyPI version](https://badge.fury.io/py/pefile.svg)](https://badge.fury.io/py/pefile)\n![pefile test](https://github.com/erocarrera/pefile/actions/workflows/tests.yaml/badge.svg)\n![Coverage](https://img.shields.io/endpoint?url=https://gist.githubusercontent.com/erocarrera/2150adbc4ea8c61e381fdb9da0943723/raw/covbadge.json)\n[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/erocarrera/pefile/badge)](https://scorecard.dev/viewer/?uri=github.com/erocarrera/pefile)\n[![Contributors](https://img.shields.io/github/contributors/erocarrera/pefile)](https://github.com/erocarrera/pefile/graphs/contributors)\n[![Code style: black](https://img.shields.io/badge/code%20style-black-000000.svg)](https://github.com/psf/black)\n[![Downloads](https://static.pepy.tech/badge/pefile/month)](https://pepy.tech/project/pefile)\n[![Downloads](https://static.pepy.tech/badge/pefile)](https://pepy.tech/project/pefile)\n\n\n_pefile_ is a multi-platform Python module to parse and work with [Portable Executable (PE) files](https://en.wikipedia.org/wiki/Portable_Executable). Most of the information contained in the PE file headers is accessible, as well as all the sections' details and data.\n\nThe structures defined in the Windows header files will be accessible as attributes in the PE instance. The naming of fields/attributes will try to adhere to the naming scheme in those headers. Only shortcuts added for convenience will depart from that convention.\n\n_pefile_ requires some basic understanding of the layout of a PE file — with it, it is possible to explore nearly every single feature of the PE file format.\n\n### Installation\n\nTo install pefile through pip:\n\n`pip3 install pefile`\n\n## Features\n\nSome of the tasks that pefile makes possible are:\n\n* Inspecting headers\n* Analyzing of sections' data\n* Retrieving embedded data\n* [Reading strings from the resources](https://github.com/erocarrera/pefile/blob/wiki/ReadingResourceStrings.md)\n* Warnings for suspicious and malformed values\n* Basic modifying of PEs, like [writing to some fields](https://github.com/erocarrera/pefile/blob/wiki/UsageExamples.md#reading-and-writing-standard-header-members) and [other parts](https://github.com/erocarrera/pefile/blob/wiki/ModifyingPEImageData.md) of the PE\n  * This functionality won't rearrange PE file structures to make room for new fields, so use it with care.\n  * Overwriting fields should mostly be safe.\n* Packer detection with [PEiD’s signatures](https://github.com/erocarrera/pefile/blob/wiki/PEiDSignatures.md)\n* [PEiD signature](https://github.com/erocarrera/pefile/blob/wiki/PEiDSignatures.md) generation\n\nPlease, refer to [Usage Examples](https://github.com/erocarrera/pefile/blob/wiki/UsageExamples.md#introduction) for some code snippets that demonstrate how to use _pefile_.\n\nHere are a few examples of what a dump produced with _pefile_ looks like for different types of files:\n\n* [a packed file](https://github.com/erocarrera/pefile/blob/wiki/FullDump0x90.md)\n* [kernel32.dll](https://github.com/erocarrera/pefile/blob/wiki/FullDumpKernel32.md)\n* [TinyPE](https://github.com/erocarrera/pefile/blob/wiki/FullDumpTinyPE.md)\n\nTo work with authenticated binaries, including **Authenticode signatures**, please check the project [verify-sigs](https://code.google.com/archive/p/verify-sigs/).\n\n_pefile_ runs in several pipelines scanning hundreds of thousands of new PE files every day, and, while not perfect, it has grown to be pretty robust over time. That being said, small glitches are found now and then. If you bump into a PE that does not appear to be processed correctly, do report it, please! It will help make pefile a tiny bit more powerful.\n\n## Dependencies\n\n_pefile_ is self-contained. The module has no dependencies; it is endianness independent; and it works on Windows, macOS, and Linux.\n\n## Projects and products using _pefile_\n\n  * Didier Stevens' [pecheck](https://blog.didierstevens.com/2018/06/12/update-pecheck-py-version-0-7-3/), a tool for displaying PE file info, handles PEiD files better then _pefile_ does.\n  * [MAEC](https://maecproject.github.io/), a standardized language for encoding and communicating high-fidelity information about malware based upon attributes such as behaviors, artifacts, and attack patterns. MAEC [converts](https://github.com/MAECProject/pefile-to-maec) _pefile_'s output into their XML format.\n  * [Qiew](https://github.com/mtivadar/qiew), a Hex/File format viewer.\n  * [VirusTotal](https://www.virustotal.com/)\n  * [bbfreeze](https://pypi.org/project/bbfreeze/)\n  * **pyemu**: [download](https://www.openrce.org/repositories/browse/codypierce), [GitHub](https://github.com/codypierce/pyemu), [whitepaper](https://www.blackhat.com/presentations/bh-usa-07/Pierce/Whitepaper/bh-usa-07-pierce-WP.pdf)\n  * [Immunity Debugger 1.1](https://www.openrce.org/blog/view/882/Immunity_Debugger_v1.1_Release)\n  * [Cuckoo](https://github.com/cuckoosandbox/cuckoo)\n  * [CAPE](https://github.com/kevoreilly/CAPEv2)\n  * [MultiScanner](https://github.com/mitre/multiscanner)\n  * [PE Tree](https://github.com/blackberry/pe_tree)\n  * [icoextract](https://github.com/jlu5/icoextract)\n\n## Additional resources\n\nPDFs of posters depicting the PE file format:\n\n  * [Portable Executable Format Layout](https://drive.google.com/file/d/0B3_wGJkuWLytbnIxY1J5WUs4MEk/view?usp=sharing\u0026resourcekey=0-n5zZ2UW39xVTH8ZSu6C2aQ) shows the full view of the headers and structures defined by the PE format.\n  * [Portable Executable Header Walkthrough](https://drive.google.com/file/d/0B3_wGJkuWLytQmc2di0wajB1Xzg/view?resourcekey=0-coPypA_IwxaOCPwl1_4u2g) shows the raw view of an executable file with the PE format fields laid out over the corresponding areas.\n\nThe following links provide detailed information about the PE format and its structures.\n\n  * [corkami's wiki page about the PE format](https://web.archive.org/web/20150821170441/https://code.google.com/p/corkami/wiki/PE) (archive) has grown to be one of the most in-depth repositories of information about the PE format.\n  * [corkami's treasure trove of PE weirdness](https://github.com/corkami/pocs/tree/master/PE)\n  * [An In-Depth Look into the Win32 Portable Executable File Format](https://learn.microsoft.com/en-us/archive/msdn-magazine/2002/february/inside-windows-win32-portable-executable-file-format-in-detail)\n  * [An In-Depth Look into the Win32 Portable Executable File Format, Part 2](https://learn.microsoft.com/en-us/archive/msdn-magazine/2002/march/inside-windows-an-in-depth-look-into-the-win32-portable-executable-file-format-part-2)\n  * [Microsoft Portable Executable and Common Object File Format Specification](https://learn.microsoft.com/en-us/windows/win32/debug/pe-format)\n  * [The Portable Executable File Format](https://web.archive.org/web/20220804184037/http://www.csn.ul.ie/~caolan/publink/winresdump/winresdump/doc/pefile.html) (archive)\n  * [Get icons from Exe or DLL the PE way](https://web.archive.org/web/20250819092225/https://www.codeproject.com/Articles/9303/Get-icons-from-Exe-or-DLL-the-PE-way) (archive)\n  * Solar Eclipse's Tiny PE page at \"http://www.phreedom.org/solar/code/tinype/\" is no longer available ([html-only archive](https://web.archive.org/web/20111001045025/http://www.phreedom.org/solar/code/tinype/)), corkami's TinyPE is available [here](https://github.com/corkami/pocs/blob/master/PE/tiny.asm) (Code only)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ferocarrera%2Fpefile","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ferocarrera%2Fpefile","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ferocarrera%2Fpefile/lists"}