PE Parser: A Python package for Portable Executable files processing

Daniel Gibert · Software Impacts · 2022

PE Parser is a Python package to parse and work with the hexadecimal representation of executables' binary content and its assembly language source code. PE Parser has been designed to provide a class-based and user-friendly interface for the extraction of well-known features commonly used for the task of malware detection and classification such as byte and opcode N-Grams, API function calls, the frequency of use of the registers, characteristics of the Portable Executable file sections, among others. In addition, PE Parser has various command line tools to visualize the executables as grayscale images or as a stream of entropy values.

Read the paper · More papers on PaperTik