Skip to content

exec-pe-forensic

Parse a Windows PE binary and get MITRE-tagged forensic detections in three lines of Rust.

use exec_pe_core::parser::parse_pe_path;
use exec_pe_analysis::detect_all;

let pe = parse_pe_path("suspicious.exe")?;
for hit in detect_all(&pe) {
    println!("[{}] {} — {}", hit.mitre_technique_id, hit.tactic, hit.description);
}
[T1027.002] defense-evasion — Packed/protected section 'UPX0' (entropy 7.82, known packer name)
[T1055]     defense-evasion — Suspicious API import: 'VirtualAllocEx'
[T1055]     defense-evasion — Suspicious API import: 'WriteProcessMemory'
[T1055]     defense-evasion — Suspicious API import: 'CreateRemoteThread'
[T1486]     impact          — QWCrypt/RedCurl IOC '.qwCrypt' found in PE string table
[T1562.001] defense-evasion — AV exclusion fragment 'Windows Defender\Exclusions' found in PE string table

Install

[dependencies]
exec-pe-core     = "0.1"
exec-pe-analysis = "0.1"

The two crates are intentionally separate. exec-pe-core is a zero-IO, medium-agnostic parser: it accepts &[u8] or a file path and returns a PeFile struct. exec-pe-analysis contains the detectors; they are pure functions over &PeFile with no I/O of their own. You can use exec-pe-core alone if you only need structured PE metadata.

What it detects

exec-pe-analysis runs pure-function detectors over a parsed PeFile, each tagged with its MITRE ATT&CK technique:

  • Suspicious imports — process-injection and evasion API names (VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, …)
  • Packed/protected sections — known packer section names plus an entropy threshold
  • AV-exclusion fragments — defender-exclusion path strings embedded in the binary
  • IOC strings — QWCrypt/RedCurl and related campaign indicators in the PE string table

Architecture

exec-pe-forensic
├── exec-pe-core        PARSER layer — accepts &[u8] or Path, no CONTAINER/FS dependencies
│   ├── parser     goblin::pe::PE → PeFile struct (imports, sections, strings, SHA-256)
│   └── strings    extract_ascii / extract_utf16le / compute_entropy
└── exec-pe-analysis    detectors — pure fn(&PeFile) -> Vec<PeDetection>

Format constants and IOC lists live in forensicnomicon, a zero-dependency, compile-time knowledge crate. Updating an IOC list means bumping forensicnomicon, not touching any parsing logic.


Privacy Policy · Terms of Service · GitHub · © 2026 Security Ronin Ltd