This post is part of a series of posts categorized as “Wiki” that contain basic how-to information. The intent is to create a reference repository for myself, but I’m not selfish so if anyone else can also benefit from it then I’m happy to share the knowledge!

  • OS: Linux/Windows
  • Description: Section hashes, entropy, imports, API functionality summary, anomaly detection, and other helpful properties
Helpful Options:
 -o,--output    write report to output file
 -p,--picture   write image representation of the PE to output file
 --diff         compare several files and show common characteristics
 --pdiff        create a diff visualization
 -i,--ico       extract icons from the resource section as .ico file