PEAnatomist shows almost all known data structures inside a PE file and makes some analytics. Current version provides an entropy histogram possibly handy for cursory PE forensics.
Linking to Internet Archive.
Category: | |
Runs on: | WinXP / Vista / Win7 / Win8 / Win10 |
Writes settings to: | Application folder |
Stealth: ? | Yes |
Unicode support: | Yes |
License: | MIT License |
How to extract: | Download the ZIP package and extract to a folder of your choice. Launch PEAnatomist.exe. |
Similar/alternative apps: | PPEE, MiTeC EXE Explorer, pestudio |
What's new? | See: https://rammerlabs.alidml.ru/changelog-eng.html |
PE Anatomist changelog history:
https://rammerlabs.alidml.ru/changelog-eng.html
v0.1.9
PEanatomist notably includes (since v0.2.4) a colorful byte-level entropy(*) histogram of the file under analysis, possibly handy for inquiring minds dabbling in PE forensics ?
* Everything you always wanted to know about entropy histograms but were scared to ask...;-)
https://crucialsecurity.wordpress.com/tag/entropy/
v0.2.5