With Windows being one of the most popular operating systems in the world, most software in the cyber world has been written for it. This includes malware.
This chapter focuses on the analysis of the Windows native executable, the PE file, and evolves directly by doing file analysis, that is, gathering static information and performing dynamic analysis. We will dig deeper into understanding how the PE file behaves with the Windows operating system. The following topics will be covered in this chapter:
- Analyzing Windows PE
- Tools
- Static analysis
- Dynamic analysis