Your download link is at the very bottom of the page... always.

Processed through Paypal
No account required.

Donate Bitcoin to this wallet:
Donate Ethereum to this wallet:
Donate Litecoin to this wallet:

Buying our over-priced stuff helps us keep things running. Peruse here.

Join our Facebook groupFollow us on TwitterFollow us on Instagram

 Home » Freeware Downloads » Anti-Virus, Anti-Malware, Security Utilities » Malware Diagnostic Tools » PE Anatomist v0.1.18   
File - Download PE Anatomist v0.1.18

Always scroll to the bottom of the page for the download link.
We don't believe in fake/misleading download buttons and tricks. The link is always in the same place.

PE Anatomist v0.1.18

PE Anatomist shows almost all known data structures inside a PE file and makes some analytics.

Headers and data structures parsing

IMAGE_DOS_HEADER, IMAGE_FILE_HEADER, IMAGE_OPTIONAL_HEADER, IMAGE_OPTIONAL_HEADER64 and the DataDirectories List with additional information about some fields
Table of COFF symbols
Sections table, supporting long section names (via symbols table) and entropy calculating
Import table (supports MS-styled names demangling)
Bound Import Table
Delayed Import Table
Export Table with additional info
Resource Table with additional info about different resource types and detailed view for all types
Base Relocation Table. Target address determining and interpretation available for all supporting architectures. It detects imports, delayed imports, exports, tables from loadconfig directory, ANSI and UNICODE strings.
Brief info about PE Authenticode Signature
LoadConfig Directory with SEH, GFID, decoded CFG bitmap, GIAT, Guard LongJumps, CHPE Metadata, Dynamic Value Reloc Table, Enclave Configuration, Volatile Metadata tables parsing and additional information about some fields
Debug Directory. It parses contents of CODEVIEW, POGO, VC FEATURE, REPRO, FPO, EXDLL CHARACTERISTICS, SPGO debug types
TLS config and callbacks table with additional information about some fields
Exceptions Data Table. x64 (including version 2 with EPILOG unwind codes), arm, arm64, ia64 architectures are support, as well as chain of unwind data for x64, language-specific handler data (C Scope, C++ FuncInfo, C++ EH4, C++ DWARF LSDA) and hexadecimal view of unwind data
Partial .NET directory pasring: IMAGE_COR20_HEADER, CORCOMPILE_HEADER, READYTORUN_HEADER with additional information about some fields
Decode Rich signature indicating the tool used, the action being taken, the full version of the tool, and the version of VisualStudio to which the tool belongs
IAT table contents
VB5 and VB6 typical structures: project info, DLLCall-imports, referenced modules, object table

In addition

FLC - file location calculator
Display settings and sorting by any column of the list
Localization of the program interface (while Russian and English options are available) via external DLL file
Explorer's context menu integration
Decoding strings of national Unicode symbols (cyrillic form CP1251 is available now)

More information here.

MD5: E6A17F1B8BC3818F72831E41519F7B4E
SHA1: AD6019C4353107B3FB6E59EAC904519BB0A35F4D
SHA256: DEE738EAEE269D4556F140413C06DD4CFFECADC9F38EC7931537CD5D2549F31D

This tool was designed to be used with:

Windows XP SP3 (x86)
Windows 7, Windows 8, Windows 8.1, Windows 10 (both x86 and x64)
ReactOS 0.4

File Formats


PE Image Architectures

Intel x86
ARM7 Thumb
Intel IA64
CHPE (x86 on ARM8-64)

Version (2020-10-21)

Fixed error displaying data from ~GUID in .NET metadata tables
Added description of flags for entries in .NET metadata tables
Fixed bug with positioning child windows on multi-monitor configurations
Added creation of a minidump in case of an unhandled exception
Updated @feat.00 flag description
Changed description text for several IDs in Rich Signature
Rewrote a part of the code to enumerate the 'Section' objects
Added a column to the ExceptionsData X64 table to display the size of the stack allocation
Added a request to start a new copy of the program when the restriction on starting the only instance of the program is enabled and running copy does not respond
ExceptionsData X64 chain table format changed to more verbose
Fixed error in determining the allocation size for UWOP_ALLOC_LARGE (1)
Added a page for xFG hash values for OBJ files
Added ExceptionsData x64, ARM64 and ARM for OBJ files
Fixed a bug with working with sections in OBJ files in the presence of BSS with a certain set of parameters
Fixed a bug with parsing unwind codes for ARM and ARM64 (in PE and OBJ files), which could appear on small files or in presence of a large number of epilogues in a function
Cleaning up and slight optimization of the IA64 unwind codes parser
Added a description of the section and an offset in it to the COFF symbol, which is referenced by the CodeView symbol in the corresponding forms of debug information
Added options to search any value less or greater than the specified
Added setting of the initial search position based on: the last found line, the selected line, or forced from the beginning of the list
Added full-text search in all columns of the list (minimum query length - 2 characters, search is case insensitive only for ANSI characters)
Added the ability to search in any list
Fixed a bug with displaying the type name from TypeDef in the .NET metadata token description in rare cases (only the method name was displayed, without the type name)

Click here to visit the author's website.
Continue below to download this file.

Downloads Views Developer Last Update Version Size Type Rank
748 2,395 RamMerLabs <img src=""border="0"> Oct 22, 2020 - 12:02 0.1.18 154.7KB ZIP 5/5, out of 10 Votes.
File Tags
Anatomist  PE  v0.1.18  
Whoa! Slow down there, Speedy.
Read this and then continue to the download.

Like seeing no ads? No misleading/fake download buttons?
We like it too! This site has been kept alive for 10 years
because of people just like you who download and donate.
No one is stopping you from downloading without donating
but the site runs on the "Honor System". If your momma
raised you to be honorable, make a donation and download
'til ya turn blue. Make your momma proud!

Thank you! -Randy & Deanna (The Older Geeks)

Monthly operating costs = $610
Donations for December = $66
Donations over our monthly goal
are set aside for future upgrades.

Processed securely through Paypal.
When you donate, it will say "Home Computer Repair LLC".
This is our computer store account.

Donate Bitcoin: 1KkUMXvQ2ko3xcJkzitB7WYgoW6m79WFfm
Donate Ethereum: 0x40E56922F43637224935CDC35e2c96E0392A8505
Donate Litecoin:LLYAFEyqjH69gkyCEpRjXNyedRCWrVChfL
Just send a check to our computer store payable to Home Computer Repair LLC.
Our address: Home Computer Repair LLC, 208 E. Water St. Mount Vernon, MO 65712

Recent Super Donors ($50+)
Thanks, Max
Thanks, Richard
Thanks, Joseph
Thanks, Myron

Recent Donors
Thanks, Scott & Associates
Thanks, James
Thanks, Owen
Thanks, Pavlin
Thanks, Martin
Thanks, Seamus
Thanks, Owen
Thanks, Lawrence
Thanks, Bitcoin donor
Thanks, James

   →→ Download Now ←← - Click to Rate File -
Like this download? Share it on Twitter →

Copyright (c) 2020