PeStudio 8.70


Information

PeStudio 8.70
Categories: System Utilities
License: Freeware
Language: English
OS: Windows All Version
Developer: Marc Ochsenmeier
Views: 653
Downloaded: 235
Rating:

Download

Share Me:

Description

PeStudio Is A Free Tool Performing The Static Analysis And Investigation Of Any Windows Executable Binary. A File Being Analyzed With PeStudio Is Never Launched. Therefore You Can Evaluate Unknown Executable And Even Malware With No Risk. PeStudio Runs On Any Windows Platform And Is Fully Portable, No Installation Is Required. PeStudio Does Not Change The System Or Leaves Anything Behind.

PeStudio Shows Indicators As A Human-friendly Result Of The Analyzed Image. Indicators Are Grouped Into Categories According To Their Severity. Indicators Show The Potential And The Anomalies Of The Application Being Analyzed. The Classifications Are Based On XML Files Provided With PeStudio. By Editing The XML File, One Can Customize The Indicators Shown And Their Severity. Among The Indicators, PeStudio Shows When An Image Is Compressed Using UPX Or MPRESS. PeStudio Helps You To Define The Trustworthiness Of The Application Being Analyzed.

PeStudio Can Query Antivirus Engines Hosted By Virustotal For The File Being Analyzed. This Feature Only Sends The MD5 Of The File Being Analyzed. This Feature Can Be Switched ON Or OFF Using An XML File Included With PeStudio. PeStudio Helps You To Determine How Suspicious The File Being Analyzed Is.

PeStudio Retrieves The Libraries And The Functions Used By The Image. PeStudio Also Includes An XML File That Is Used To Blacklist Functions (e.g. Registry, Process, Thead, File, ...). The Blacklist File Can Be Customized And Extended According To Your Own Needs. PeStudio Shows The Intent And Purpose Of The Application Analyzed.

PeStudio Analyzes The Resources Of The File Being Analyzed And Detects Embedded Items (e.g. EXE, DLL, SYS, PDF, CAB, ZIP, JAR, ...). Any Item Can Be Separately Selected And Saved To A File, Allowing The Possibility Of Further Analysis.

PeStudio Is Also Capable To Detect And Proceed To A RAW Handling Of The Digital Certificates (when Available) Embedded In An Image. PeStudio Can Produce An XML Output Report File Documenting The Executable File Being Analyzed. PeStudio Runs As A Graphical User Interface GUI Or A Command Line Interface CLI. Starting PeStudio In A Prompt Mode Allows The Analysis Of Executables And The Creation Of The XML Output File In A Batch Mode Mechanism.

Related Software

Categories: System Utilities
OS: Windows All Version
Views: 476
Downloads: 182
Categories: System Utilities
OS: Windows All Version
Views: 595
Downloads: 174
Categories: System Utilities
OS: Windows All Version
Views: 403
Downloads: 126
Categories: System Utilities
OS: Windows All Version
Views: 441
Downloads: 198
Categories: System Utilities
OS: Windows All Version
Views: 672
Downloads: 241
Categories: System Utilities
OS: Windows All Version
Views: 839
Downloads: 284

Submit Review
Name
Email
Pros
Cons
Thoughs