Your download link is at the very bottom of the page... always.

Processed through Paypal
No account required.

Donate Bitcoin to this wallet:
Donate Ethereum to this wallet:
Donate Litecoin to this wallet:

Buy our over-priced crap to help keep things running.

Join our Facebook groupFollow us on TwitterFollow us on InstagramOur RSS Feed

 Home » Freeware Downloads » Anti-Virus, Anti-Malware, Security Utilities » Malware Diagnostic Tools » PEAnatomist v0.2.7   
File - Download PEAnatomist v0.2.7

Always scroll to the bottom of the page for the download link.
We don't believe in fake/misleading download buttons and tricks. The link is always in the same place.

PEAnatomist v0.2.7

Want to look inside PE format?

The free PEAnatomist utility supports almost all known and some undocumented structures inside MS PortableExecutable files (EXE, DLL, SYS and the like), LIB files and object files in COFF, MSVC CxxIL and ExtendedObj formats, and also performs simple analysis of the received data.

File Formats

COFF Object
MSVC IntermediateLanguage AnonCOFF Object File (MSVC CxxIL)
AnonCOFF ExtendedObj
Objects Library

PE Image Architectures

Intel x86
ARM7 Thumb
Intel IA64
CHPE (x86 on ARM)
ARM64X (x64 on ARM64)

A little of supported headers and data structures

PE: IMAGE_DOS_HEADER, IMAGE_FILE_HEADER, IMAGE_OPTIONAL_HEADER, IMAGE_OPTIONAL_HEADER64 and the DataDirectories List with additional information about some fields
PE: Table of COFF symbols
PE: Sections table, supporting long section names (via symbols table) and entropy calculating
PE: Import table (supports MS-styled names demangling)
PE: Bound Import Table
PE: Delayed Import Table
PE: Export Table with additional info
PE: Resource Table with additional info about different resource types and detailed view for all types
PE: Base Relocation Table. Target address determining and interpretation available for all supporting architectures. It detects imports, delayed imports, exports, tables from loadconfig directory, ANSI and UNICODE strings.
PE: Brief info about PE Authenticode Signature
PE: LoadConfig Directory with SEH, GFID, decoded CFG bitmap, GIAT, CFG LongJumps, CHPE Metadata, ARM64X Metadata, Dynamic Value Reloc Table, Enclave Configuration, Volatile Metadata, CFG Eh Continuations tables parsing and additional information about some fields
PE: Debug Directory. It parses contents of CODEVIEW, POGO, VC FEATURE, REPRO, FPO, EXDLL CHARACTERISTICS, SPGO debug types
PE: TLS config and callbacks table with additional information about some fields
PE: Exceptions Data Table. x64 (including version 2 with EPILOG unwind codes), arm, arm64, ia64 architectures are support, as well as chain of unwind data for x64, language-specific handler data (C Scope, C++ FuncInfo, C++ EH4, C++ DWARF LSDA) and hexadecimal view of unwind data
PE: COM Descriptor directory pasring: headers, tables and metadata info available. Some of NGEN and ReadyToRun headers are also included
PE: Decode Rich signature indicating the tool used, the action being taken, the full version of the tool, and the version of VisualStudio to which the tool belongs
PE: IAT table contents
PE: VB5 and VB6 typical structures: project info, DLLCall-imports, referenced modules, object table
PE: Detecting an ANSI and Unicode encoded strings
PE: Plotting entropy
OBJ: COFF symbol table with decoding and @feat.00, as well as auxiliary symbols
OBJ: Section table and relocations for the selected section
OBJ: Exceptions Data Table. x64 (including version 2 with EPILOG unwind codes), arm, arm64, ia64 architectures are support, as well as chain of unwind data for x64
OBJ: Functions xFG-hash values table
OBJ: Table of CodeView Debug Symbols
OBJ: Table of CodeView Types
OBJ: Table of MSVC CxxIL Types (.cil$db)
OBJ: Table of MSVC CxxIL Global Symbols (.cil$gl)
OBJ: Table of MSVC CxxIL Local Symbols (.cil$sy)
LIB: List of archive members
LIB: The first and second (if available) linker members
LIB: Summary table of import elements IMPORT_OBJECT_HEADER, if any

ZIP-file hash:
MD5: AE138A11858D993DBBB6AC8C66760D66
SHA1: 4E4393717C3912CEDADE97A966DE99B2EA2F5A19
SHA256: DF6CC894D8E6A4C7F140B1504B24678B73E34D3C55C272DFB292E6403229A587

This tool was designed to be used with:

Windows XP SP3 (x86), Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11, ReactOS 0.4 and newer

The new version highlights
Entropy calculation with configurable block overlap for entropy graph
Ability to save several PE resources or LIB members to a file at once
A page describing WoW thunks in hybrid PE (ARM64EC, ARM64X)
Fixed error in processing the exception table for emulated architecture code in hybrid PE (ARM64EC)
Improved compatibility with certain older versions of MS Visual Studio

Changes: (2022-01-03)
1B16.009: Fixed bug in RVA description for delayed import
1B1A.010: Fixed bug with scaling delta value in IMAGE_DYNAMIC_RELOCATION_ARM64X
1C01.011: Removed handling of irrelevant command line parameter "-pe"
1C01.012: An instance of the program will not start after a message about an unknown file format if it is loaded from the command line
1C01.016: Eliminate starting a new instance of the application in the case of an unknown file format on the command line if the limitation for one instance is enabled
1C04.041: Slightly updated appearance of the entropy graph
1C04.049: Fixed a number of inaccuracies in the drawing of the entropy graph and the tooltip contents
1C04.050: Accelerated search with selection of all found lines in some cases
1C08.066: Added calculation of entropy by "sliding window" with configurable block overlap for the graph
1C08.067: Fixed behavior during TabStop navigation on some tabs of the program settings dialog
1C09.068: Fixed IMAGE_LOAD_CONFIG_DIRECTORY parsing error on some files created by linker from VS2002 pre-release versions
1C0A.073: Fixed RT_VERSION parsing error for resources created by some versions of RC/CVTRES from VS98-2003
1C13.078: Added optional display of the second line on the entropy graph with values calculated without block overlap, if the corresponding mode is enabled
1C15.083: Fixed error in processing the exception table for emulated architecture code in hybrid PE (ARM64EC)
1C15.085: Added collection of information about exception handlers (x64, ARM64) for describing RVA in emulated architecture code in hybrid PE (ARM64EC, ARM64X)
1C15.093: Added a page describing WoW thunks in hybrid PE (ARM64EC, ARM64X)
1C1A.101: All selected lines retain their state after sorting virtual lists, previously only the first of the selected lines was
1C1D.120: Added multiple saving to file for resources from PE and records from LIB
1C1E.125: Fixed a minor error in resolving an Apiset host in very rare cases (if the data for resolving in an external library was corrupted)
2101.128: Fixed error reading .NET metadata in some PE due to incorrect address alignment

Click here to visit the author's website.
Continue below to download this file.

Downloads Views Developer Last Update Version Size Type Rank
1,910 4,447 RamMerLabs <img src=""border="0"> Jan 10, 2022 - 11:35 200KB ZIP 5/5, out of 21 Votes.
File Tags
PEAnatomist  v0.2.7  
Whoa! Slow down there, Speedy.
Read this and then continue to the download.

Like seeing no ads? No misleading/fake download buttons?
We like it too! This site has been kept alive for 14 years
because of people just like you who download and donate.
No one is stopping you from downloading without donating
but the site runs on the "Honor System". If your momma
raised you to be honorable, make a donation and download
'til ya turn blue. Make your momma proud!

Thank you! -Randy & Deanna (The Older Geeks)

Monthly operating costs = $725
Donations for May = $1,249
Donations over our monthly goal
are set aside for future upgrades and
handed-over to Deanna for new shoes.

Processed securely through Paypal.
No PayPal account required.
Your bank statement will read: "Home Computer Repair LLC".
This is our computer store.


Just send a check to our computer store payable to Home Computer Repair LLC.
Our address: Home Computer Repair LLC, 208 E. Water St. Mount Vernon, MO 65712

Recent Super Donors ($50+)
Thanks, Warren
Thanks, Sherry
Thanks, AskWoodyTech
Thanks, Gregory
Thanks, Samuel

Recent Donors
Thanks, John
Thanks, Stan
Thanks, Stephen
Thanks, Dennis
Thanks, Tibor
Thanks, Steven
Thanks, Graham
Thanks, Roberto
Thanks, Eduardo
Thanks, Carol

   →→ Download Now ←← - Click to Rate File -
Like this download? Share it on Twitter → Copyright (c) 2022