LIEF: Library to Instrument Executable Formats Version 2.0.0
Loading...
Searching...
No Matches
PE/Binary.hpp
Go to the documentation of this file.
1/* Copyright 2017 - 2026 R. Thomas
2 * Copyright 2017 - 2026 Quarkslab
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16#ifndef LIEF_PE_BINARY_H
17#define LIEF_PE_BINARY_H
18
19#include <memory>
20
21#include "LIEF/PE/Builder.hpp"
24#include "LIEF/PE/DosHeader.hpp"
25#include "LIEF/PE/Header.hpp"
26#include "LIEF/PE/Import.hpp"
30
31#include "LIEF/COFF/String.hpp"
32#include "LIEF/COFF/Symbol.hpp"
33
35
37#include "LIEF/visibility.h"
38
39
41namespace LIEF::PE {
42class ExceptionInfo;
43class CodeViewPDB;
44class Debug;
45class Export;
47class Parser;
48class Relocation;
49class ResourceData;
51class ResourceNode;
52class RichHeader;
53class TLS;
54class Factory;
55
59 friend class Parser;
60 friend class Builder;
61 friend class Factory;
62
63 public:
65 using sections_t = std::vector<std::unique_ptr<Section>>;
66
69
72
74 using data_directories_t = std::vector<std::unique_ptr<DataDirectory>>;
75
78
82
84 using relocations_t = std::vector<std::unique_ptr<Relocation>>;
85
88
92
94 using imports_t = std::vector<std::unique_ptr<Import>>;
95
98
101
103 using delay_imports_t = std::vector<std::unique_ptr<DelayImport>>;
104
107
111
113 using debug_entries_t = std::vector<std::unique_ptr<Debug>>;
114
117
121
123 using symbols_t = std::vector<std::unique_ptr<COFF::Symbol>>;
124
127
131
133 using strings_table_t = std::vector<COFF::String>;
134
137
140
142 using signatures_t = std::vector<Signature>;
143
146
149
151 using exceptions_t = std::vector<std::unique_ptr<ExceptionInfo>>;
152
155
159
161 ~Binary() override;
162
164 PE_TYPE type() const {
165 return type_;
166 }
167
172 uint64_t rva_to_offset(uint64_t RVA) const;
173
176 uint64_t va_to_offset(uint64_t VA) const {
177 uint64_t rva = VA - optional_header().imagebase();
178 return rva_to_offset(rva);
179 }
180
186 uint64_t slide = 0) const override;
187
189 uint64_t offset_to_rva(uint64_t offset) const;
190
194 uint64_t imagebase() const override {
195 return optional_header().imagebase();
196 }
197
202 return const_cast<Section*>(
203 static_cast<const Binary*>(this)->section_from_offset(offset)
204 );
205 }
206 const Section* section_from_offset(uint64_t offset) const LIEF_LIFETIMEBOUND;
207
211 Section* section_from_rva(uint64_t virtual_address) LIEF_LIFETIMEBOUND {
212 return const_cast<Section*>(
213 static_cast<const Binary*>(this)->section_from_rva(virtual_address)
214 );
215 }
216 const Section*
217 section_from_rva(uint64_t virtual_address) const LIEF_LIFETIMEBOUND;
218
221 return sections_;
222 }
223
225 return sections_;
226 }
227
230 return dos_header_;
231 }
232
234 return dos_header_;
235 }
236
239 return header_;
240 }
241
243 return header_;
244 }
245
249 return optional_header_;
250 }
251
253 return optional_header_;
254 }
255
261 uint32_t compute_checksum() const;
262
265 uint64_t virtual_size() const override;
266
268 uint32_t sizeof_headers() const;
269
272 return tls_.get();
273 }
274
275 const TLS* tls() const LIEF_LIFETIMEBOUND {
276 return tls_.get();
277 }
278
281
283 bool has_tls() const {
284 return tls_ != nullptr;
285 }
286
289
293 bool has_imports() const {
294 return !imports_.empty();
295 }
296
300 bool has_signatures() const {
301 return !signatures_.empty();
302 }
303
307 bool has_exports() const {
308 return export_ != nullptr;
309 }
310
312 bool has_resources() const {
313 return resources_ != nullptr;
314 }
315
317 bool has_exceptions() const {
318 if (const DataDirectory* dir = exceptions_dir()) {
319 return dir->size() > 0;
320 }
321 return false;
322 }
323
327 bool has_relocations() const {
328 return !relocations_.empty();
329 }
330
332 bool has_debug() const {
333 return !debug_.empty();
334 }
335
337 bool has_configuration() const {
338 return loadconfig_ != nullptr;
339 }
340
346
349 return signatures_;
350 }
351
353 return signatures_;
354 }
355
368
382
385 std::vector<uint8_t> authentihash(ALGORITHMS algo) const;
386
389 return export_.get();
390 }
391
393 return export_.get();
394 }
395
397
400 return symbols_;
401 }
402
404 return symbols_;
405 }
406
409 return strings_table_;
410 }
411
413 return strings_table_;
414 }
415
421 auto it = std::find_if(strings_table_.begin(), strings_table_.end(),
422 [offset](const COFF::String& item) {
423 return offset == item.offset();
424 });
425 return it == strings_table_.end() ? nullptr : &*it;
426 }
427
428 const COFF::String* find_coff_string(uint32_t offset) const LIEF_LIFETIMEBOUND {
429 return const_cast<Binary*>(this)->find_coff_string(offset);
430 }
431
434 return resources_.get();
435 }
436
438 return resources_.get();
439 }
440
444
446 set_resources(std::unique_ptr<ResourceNode> root) LIEF_LIFETIMEBOUND;
447
451
456 Section* get_section(const std::string& name) LIEF_LIFETIMEBOUND {
457 return const_cast<Section*>(
458 static_cast<const Binary*>(this)->get_section(name)
459 );
460 }
461 const Section* get_section(const std::string& name) const LIEF_LIFETIMEBOUND;
462
465 const Section* import_section() const;
467 return const_cast<Section*>(
468 static_cast<const Binary*>(this)->import_section()
469 );
470 }
471
477 void remove_section(const std::string& name, bool clear = false) override;
478
482 void remove(const Section& section, bool clear = false);
483
486
489 return relocations_;
490 }
491
493 return relocations_;
494 }
495
498
501
504 return data_directories_;
505 }
506
508 return data_directories_;
509 }
510
513 return const_cast<DataDirectory*>(
514 static_cast<const Binary*>(this)->data_directory(type)
515 );
516 }
517 const DataDirectory*
519
522 return data_directory(type) != nullptr;
523 }
524
527 return debug_;
528 }
529
531 return debug_;
532 }
533
536
538 bool remove_debug(const Debug& entry);
539
542
545
547 return const_cast<CodeViewPDB*>(
548 static_cast<const Binary*>(this)->codeview_pdb()
549 );
550 }
551
555 return loadconfig_.get();
556 }
557
559 return loadconfig_.get();
560 }
561
564 return overlay_;
565 }
566
568 return overlay_;
569 }
570
572 uint64_t overlay_offset() const {
573 return overlay_offset_;
574 }
575
578 return dos_stub_;
579 }
580
582 return dos_stub_;
583 }
584
586 void dos_stub(std::vector<uint8_t> content) {
587 dos_stub_ = std::move(content);
588 }
589
592 return rich_header_.get();
593 }
594
596 return rich_header_.get();
597 }
598
601
603 bool has_rich_header() const {
604 return rich_header_ != nullptr;
605 }
606
609 return imports_;
610 }
611
613 return imports_;
614 }
615
619 Import* get_import(const std::string& import_name) LIEF_LIFETIMEBOUND {
620 return const_cast<Import*>(
621 static_cast<const Binary*>(this)->get_import(import_name)
622 );
623 }
624
625 const Import*
626 get_import(const std::string& import_name) const LIEF_LIFETIMEBOUND;
627
629 bool has_import(const std::string& import_name) const {
630 return get_import(import_name) != nullptr;
631 }
632
634 bool has_delay_imports() const {
635 return !delay_imports_.empty();
636 }
637
640 return delay_imports_;
641 }
642
644 return delay_imports_;
645 }
646
650 get_delay_import(const std::string& import_name) LIEF_LIFETIMEBOUND {
651 return const_cast<DelayImport*>(
652 static_cast<const Binary*>(this)->get_delay_import(import_name)
653 );
654 }
655 const DelayImport*
656 get_delay_import(const std::string& import_name) const LIEF_LIFETIMEBOUND;
657
658
660 bool has_delay_import(const std::string& import_name) const {
661 return get_delay_import(import_name) != nullptr;
662 }
663
668 Import& add_import(const std::string& name,
669 int32_t pos = -1) LIEF_LIFETIMEBOUND {
670 if (pos < 0 || (size_t)pos >= imports_.size()) {
671 imports_.push_back(std::make_unique<Import>(name));
672 return *imports_.back();
673 }
674 return **imports_.insert(imports_.begin() + pos,
675 std::make_unique<Import>(name));
676 }
677
681 bool remove_import(const std::string& name);
682
685 imports_.clear();
686 }
687
689 std::unique_ptr<Builder> write(const std::string& filename) {
690 return write(filename, Builder::config_t());
691 }
692
695 std::unique_ptr<Builder> write(const std::string& filename,
696 const Builder::config_t& config);
697
702 std::unique_ptr<Builder> write(std::ostream& os) {
703 return write(os, Builder::config_t());
704 }
705
706 std::unique_ptr<Builder> write(std::ostream& os,
707 const Builder::config_t& config);
708
709 void accept(Visitor& visitor) const override;
710
716 void patch_address(uint64_t address, const std::vector<uint8_t>& patch_value,
717 VA_TYPES addr_type = VA_TYPES::AUTO) override;
718
719
727 void patch_address(uint64_t address, uint64_t patch_value,
728 size_t size = sizeof(uint64_t),
729 VA_TYPES addr_type = VA_TYPES::AUTO) override;
730
731
733 void fill_address(uint64_t address, size_t size, uint8_t value = 0,
734 VA_TYPES addr_type = VA_TYPES::AUTO);
735
743 uint64_t virtual_address, uint64_t size,
745 ) const LIEF_LIFETIMEBOUND override;
746
749 uint64_t entrypoint() const override {
750 return optional_header_.imagebase() + optional_header_.addressof_entrypoint();
751 }
752
754 bool is_pie() const override {
755 return optional_header_.has(OptionalHeader::DLL_CHARACTERISTICS::DYNAMIC_BASE);
756 }
757
759 bool has_nx() const override {
760 return optional_header_.has(OptionalHeader::DLL_CHARACTERISTICS::NX_COMPAT);
761 }
762
763 uint64_t last_section_offset() const;
764
769
773
778
782
787
791
796
800
806
810
815
819
824
828
833
837
842
846
851
855
860
864
869
872
875
882 return exceptions_;
883 }
884
886 return exceptions_;
887 }
888
895
897 return const_cast<Binary*>(this)->find_exception_at(rva);
898 }
899
901 bool is_arm64ec() const;
902
905 bool is_arm64x() const;
906
917 const Binary* nested_pe_binary() const {
918 return nested_.get();
919 }
920
922 return nested_.get();
923 }
924
926 result<uint64_t> get_function_address(const std::string& name) const override;
927
928 static bool classof(const LIEF::Binary* bin) {
929 return bin->format() == Binary::FORMATS::PE;
930 }
931
932 std::ostream& print(std::ostream& os) const override;
933
934
938 LIEF_LOCAL std::unique_ptr<Binary> move_nested_pe_binary() {
939 auto ret = std::move(nested_);
940 nested_ = nullptr;
941 return ret;
942 }
943
944 private:
945 struct sizing_info_t {
946 uint32_t nb_tls_callbacks = 0;
947 uint32_t load_config_size = 0;
948 };
949
952 result<uint64_t> make_space_for_new_section();
953
955 LIEF::Binary::symbols_t get_abstract_symbols() override;
956
957 LIEF::Header get_abstract_header() const override {
958 return LIEF::Header::from(*this);
959 }
960
962 LIEF::Binary::sections_t get_abstract_sections() override;
963
964 LIEF::Binary::relocations_t get_abstract_relocations() override;
965
966 LIEF::Binary::functions_t get_abstract_exported_functions() const override;
967 LIEF::Binary::functions_t get_abstract_imported_functions() const override;
968 std::vector<std::string> get_abstract_imported_libraries() const override;
969
970 void update_lookup_address_table_offset();
971 void update_iat();
972 void shift(uint64_t from, uint64_t by);
973
974 PE_TYPE type_ = PE_TYPE::PE32_PLUS;
975 DosHeader dos_header_;
976 Header header_;
977 OptionalHeader optional_header_;
978
979 int32_t available_sections_space_ = 0;
980
981 signatures_t signatures_;
982 sections_t sections_;
983 data_directories_t data_directories_;
984 symbols_t symbols_;
985 strings_table_t strings_table_;
986 relocations_t relocations_;
987 imports_t imports_;
988 delay_imports_t delay_imports_;
989 debug_entries_t debug_;
990 exceptions_t exceptions_;
991 uint64_t overlay_offset_ = 0;
992 std::vector<uint8_t> overlay_;
993 std::vector<uint8_t> dos_stub_;
994 std::vector<uint8_t> section_offset_padding_;
995
996 std::unique_ptr<RichHeader> rich_header_;
997 std::unique_ptr<Export> export_;
998 std::unique_ptr<ResourceNode> resources_;
999 std::unique_ptr<TLS> tls_;
1000 std::unique_ptr<LoadConfiguration> loadconfig_;
1001 std::unique_ptr<Binary> nested_;
1002
1003 sizing_info_t sizing_info_;
1004};
1005
1006}
1007
1008#endif
Generic interface representing a binary executable.
Definition Abstract/Binary.hpp:60
std::vector< Function > functions_t
Definition Abstract/Binary.hpp:83
@ PE
Definition Abstract/Binary.hpp:78
FORMATS format() const
Executable format (ELF, PE, Mach-O) of the underlying binary.
Definition Abstract/Binary.hpp:125
std::vector< Symbol * > symbols_t
Internal container.
Definition Abstract/Binary.hpp:95
VA_TYPES
Enumeration of virtual address types used for patching and memory access.
Definition Abstract/Binary.hpp:63
@ AUTO
Automatically determine if the address is absolute or relative (default behavior).
Definition Abstract/Binary.hpp:66
std::vector< Section * > sections_t
Internal container.
Definition Abstract/Binary.hpp:86
std::vector< Relocation * > relocations_t
Internal container.
Definition Abstract/Binary.hpp:104
This class represents a string located in the COFF string table.
Definition String.hpp:35
Definition Abstract/Header.hpp:40
static Header from(const LIEF::ELF::Binary &elf)
OptionalHeader & optional_header()
Header that follows the header(). It is named optional from the COFF specification but it is mandator...
Definition PE/Binary.hpp:248
ref_iterator< sections_t &, Section * > it_sections
Iterator that outputs Section& object.
Definition PE/Binary.hpp:68
const DataDirectory * export_dir() const
Definition PE/Binary.hpp:770
std::vector< std::unique_ptr< DelayImport > > delay_imports_t
Internal container for storing PE's DelayImport.
Definition PE/Binary.hpp:103
void remove_all_relocations()
Remove all the relocations.
DataDirectory * export_dir()
Return the data directory associated with the export table.
Definition PE/Binary.hpp:766
it_exceptions exceptions()
Iterator over the exception (_RUNTIME_FUNCTION) functions.
Definition PE/Binary.hpp:881
std::unique_ptr< Builder > write(std::ostream &os)
Reconstruct the binary object and write the raw PE in os stream.
Definition PE/Binary.hpp:702
std::vector< uint8_t > authentihash(ALGORITHMS algo) const
Compute the authentihash according to the algorithm provided in the first parameter.
ref_iterator< data_directories_t &, DataDirectory * > it_data_directories
Iterator that outputs DataDirectory&.
Definition PE/Binary.hpp:77
void remove_tls()
Remove the TLS from the binary.
const LoadConfiguration * load_configuration() const
Return the LoadConfiguration object or a nullptr if the binary does not use the LoadConfiguration.
Definition PE/Binary.hpp:554
std::ostream & print(std::ostream &os) const override
it_const_delay_imports delay_imports() const
Definition PE/Binary.hpp:643
it_const_debug_entries debug() const
Definition PE/Binary.hpp:530
void remove_section(const std::string &name, bool clear=false) override
Delete the section with the given name.
void patch_address(uint64_t address, uint64_t patch_value, size_t size=sizeof(uint64_t), VA_TYPES addr_type=VA_TYPES::AUTO) override
Patch the address with the given value.
bool is_pie() const override
Check if the binary is position independent.
Definition PE/Binary.hpp:754
LIEF::Binary::functions_t ctor_functions() const override
Return the list of the binary constructors.
DataDirectory * exceptions_dir()
Return the data directory associated with the exceptions.
Definition PE/Binary.hpp:793
std::vector< std::unique_ptr< Section > > sections_t
Internal container for storing PE's Section.
Definition PE/Binary.hpp:65
const_ref_iterator< const imports_t &, const Import * > it_const_imports
Iterator that outputs const Import&.
Definition PE/Binary.hpp:100
const_ref_iterator< const delay_imports_t &, const DelayImport * > it_const_delay_imports
Iterator that outputs const DelayImport&.
Definition PE/Binary.hpp:109
void dos_stub(std::vector< uint8_t > content)
Update the DOS stub content.
Definition PE/Binary.hpp:586
DataDirectory * delay_dir()
Return the data directory associated with delayed imports.
Definition PE/Binary.hpp:857
it_imports imports()
Return an iterator over the binary imports.
Definition PE/Binary.hpp:608
bool has_resources() const
Check if the current binary has resources.
Definition PE/Binary.hpp:312
const DataDirectory * import_dir() const
Definition PE/Binary.hpp:779
TLS & tls(const TLS &tls)
Set a TLS object in the current Binary.
const ResourceNode * resources() const
Definition PE/Binary.hpp:437
bool has_debug() const
Check if the current binary contains debug information.
Definition PE/Binary.hpp:332
const DataDirectory * iat_dir() const
Definition PE/Binary.hpp:852
DelayImport * get_delay_import(const std::string &import_name)
Returns the DelayImport matching the given name. If it can't be found, it returns a nullptr.
Definition PE/Binary.hpp:650
it_const_exceptions exceptions() const
Definition PE/Binary.hpp:885
friend class Factory
Definition PE/Binary.hpp:61
const DataDirectory * tls_dir() const
Definition PE/Binary.hpp:834
const DataDirectory * debug_dir() const
Definition PE/Binary.hpp:825
bool has_relocations() const
Check if the current binary has relocations.
Definition PE/Binary.hpp:327
bool has_exports() const
Check if the current binary has exports.
Definition PE/Binary.hpp:307
ref_iterator< strings_table_t & > it_strings_table
Iterator that outputs COFF::String&.
Definition PE/Binary.hpp:136
std::vector< std::unique_ptr< ExceptionInfo > > exceptions_t
Internal container for storing runtime function associated with exceptions.
Definition PE/Binary.hpp:151
std::vector< std::unique_ptr< Relocation > > relocations_t
Internal container for storing PE's Relocation.
Definition PE/Binary.hpp:84
uint64_t rva_to_offset(uint64_t RVA) const
Convert a Relative Virtual Address into an offset.
result< uint64_t > get_function_address(const std::string &name) const override
Attempt to resolve the address of the function specified by name.
result< ResourcesManager > resources_manager() const
Return the ResourcesManager (class to manage resources more easily than the tree one).
bool remove_import(const std::string &name)
Remove the imported library with the given name.
bool clear_debug()
Remove all debug info from the binary.
result< uint64_t > offset_to_virtual_address(uint64_t offset, uint64_t slide=0) const override
Convert the given offset into an absolute virtual address.
it_const_imports imports() const
Definition PE/Binary.hpp:612
const OptionalHeader & optional_header() const
Definition PE/Binary.hpp:252
it_signatures signatures()
Definition PE/Binary.hpp:352
Signature::VERIFICATION_FLAGS verify_signature(const Signature &sig, Signature::VERIFICATION_CHECKS checks=Signature::VERIFICATION_CHECKS::DEFAULT) const
Verify the binary with the Signature object provided in the first parameter. It can be used to verify...
Debug * add_debug_info(const Debug &entry)
Add a new debug entry.
span< const uint8_t > overlay() const
Return the overlay content.
Definition PE/Binary.hpp:563
bool is_arm64x() const
True if this binary is compiled in ARM64X mode (contains both ARM64 and ARM64EC code).
bool is_arm64ec() const
True if this binary is compiled in ARM64EC mode (emulation compatible).
DataDirectory * rsrc_dir()
Return the data directory associated with the resources tree.
Definition PE/Binary.hpp:784
const_ref_iterator< const data_directories_t &, const DataDirectory * > it_const_data_directories
Iterator that outputs const DataDirectory&.
Definition PE/Binary.hpp:80
span< const uint8_t > get_content_from_virtual_address(uint64_t virtual_address, uint64_t size, Binary::VA_TYPES addr_type=Binary::VA_TYPES::AUTO) const override
Return the content located at the provided virtual address.
const_ref_iterator< const signatures_t & > it_const_signatures
Iterator that outputs const Signature&.
Definition PE/Binary.hpp:148
const_ref_iterator< const symbols_t &, const COFF::Symbol * > it_const_symbols
Iterator that outputs const Symbol&.
Definition PE/Binary.hpp:129
std::vector< std::unique_ptr< Import > > imports_t
Internal container for storing PE's Import.
Definition PE/Binary.hpp:94
const DataDirectory * data_directory(DataDirectory::TYPES type) const
std::vector< std::unique_ptr< COFF::Symbol > > symbols_t
Internal container for storing COFF Symbols.
Definition PE/Binary.hpp:123
DataDirectory * tls_dir()
Return the data directory associated with TLS.
Definition PE/Binary.hpp:830
const DataDirectory * rsrc_dir() const
Definition PE/Binary.hpp:788
void fill_address(uint64_t address, size_t size, uint8_t value=0, VA_TYPES addr_type=VA_TYPES::AUTO)
Fill the content at the provided address with a fixed value.
ref_iterator< signatures_t & > it_signatures
Iterator that outputs Signature&.
Definition PE/Binary.hpp:145
bool has_rich_header() const
Check if the current binary has a RichHeader object.
Definition PE/Binary.hpp:603
ref_iterator< symbols_t &, COFF::Symbol * > it_symbols
Iterator that outputs Symbol&.
Definition PE/Binary.hpp:126
bool has_signatures() const
Check if the current binary contains signatures.
Definition PE/Binary.hpp:300
bool has_delay_imports() const
Check if the current binary contains delay imports.
Definition PE/Binary.hpp:634
const DataDirectory * load_config_dir() const
Definition PE/Binary.hpp:843
void rich_header(const RichHeader &rich_header)
Set a RichHeader object in the current Binary.
DataDirectory * relocation_dir()
Return the data directory associated with the relocation table.
Definition PE/Binary.hpp:812
const DataDirectory * exceptions_dir() const
Definition PE/Binary.hpp:797
TLS * tls()
Return a reference to the TLS object.
Definition PE/Binary.hpp:271
it_const_data_directories data_directories() const
Definition PE/Binary.hpp:507
uint64_t entrypoint() const override
Return the binary's entrypoint (it is the same value as OptionalHeader::addressof_entrypoint).
Definition PE/Binary.hpp:749
std::vector< Signature > signatures_t
Internal container for storing PE's authenticode Signature.
Definition PE/Binary.hpp:142
Signature::VERIFICATION_FLAGS verify_signature(Signature::VERIFICATION_CHECKS checks=Signature::VERIFICATION_CHECKS::DEFAULT) const
Verify the binary against the embedded signature(s) (if any) First, it checks that the embedded signa...
const ExceptionInfo * find_exception_at(uint32_t rva) const
Definition PE/Binary.hpp:896
const Import * get_import(const std::string &import_name) const
uint64_t last_section_offset() const
const_ref_iterator< const strings_table_t & > it_const_strings_table
Iterator that outputs const COFF::String&.
Definition PE/Binary.hpp:139
const DataDirectory * delay_dir() const
Definition PE/Binary.hpp:861
ref_iterator< relocations_t &, Relocation * > it_relocations
Iterator that outputs Relocation&.
Definition PE/Binary.hpp:87
static bool classof(const LIEF::Binary *bin)
Definition PE/Binary.hpp:928
const Section * get_section(const std::string &name) const
it_symbols symbols()
Return binary Symbols.
Definition PE/Binary.hpp:399
Section * import_section()
Definition PE/Binary.hpp:466
void accept(Visitor &visitor) const override
Method so that a visitor can visit us.
LIEF::Binary::functions_t functions() const
All functions found in the binary
LIEF::Binary::functions_t exception_functions() const
Functions found in the Exception table directory.
void patch_address(uint64_t address, const std::vector< uint8_t > &patch_value, VA_TYPES addr_type=VA_TYPES::AUTO) override
Patch the content at virtual address address with patch_value.
const Section * section_from_offset(uint64_t offset) const
uint32_t compute_checksum() const
Re-compute the value of OptionalHeader::checksum. If both values do not match, it could mean that the...
std::unique_ptr< Builder > write(std::ostream &os, const Builder::config_t &config)
friend class Builder
Definition PE/Binary.hpp:60
COFF::String * find_coff_string(uint32_t offset)
Try to find the COFF string at the given offset in the COFF string table.
Definition PE/Binary.hpp:420
ResourceNode * set_resources(std::unique_ptr< ResourceNode > root)
std::vector< COFF::String > strings_table_t
Internal container for storing strings.
Definition PE/Binary.hpp:133
uint64_t offset_to_rva(uint64_t offset) const
Convert the given offset into a relative virtual address (RVA).
~Binary() override
const_ref_iterator< const relocations_t &, const Relocation * > it_const_relocations
Iterator that outputs const Relocation&.
Definition PE/Binary.hpp:90
span< uint8_t > overlay()
Definition PE/Binary.hpp:567
const_ref_iterator< const sections_t &, const Section * > it_const_sections
Iterator that outputs const Section& object.
Definition PE/Binary.hpp:71
uint64_t overlay_offset() const
Return the original overlay offset.
Definition PE/Binary.hpp:572
const DelayImport * get_delay_import(const std::string &import_name) const
Section * section_from_rva(uint64_t virtual_address)
Find the section that encompasses the given RVA.
Definition PE/Binary.hpp:211
Section * add_section(const Section &section)
Add a section to the binary and return the section added.
const Section * import_section() const
Return the section associated with import table or a nullptr if the binary does not have an import ta...
const Export * get_export() const
Definition PE/Binary.hpp:392
ref_iterator< debug_entries_t &, Debug * > it_debug_entries
Iterator that outputs Debug&.
Definition PE/Binary.hpp:116
PE_TYPE type() const
Return PE32 or PE32+.
Definition PE/Binary.hpp:164
bool has_tls() const
Check if the current binary has a TLS object.
Definition PE/Binary.hpp:283
Export & set_export(const Export &export_table)
DataDirectory * data_directory(DataDirectory::TYPES type)
Return the DataDirectory with the given type (or index).
Definition PE/Binary.hpp:512
Section * section_from_offset(uint64_t offset)
Find the section that encompasses the given offset.
Definition PE/Binary.hpp:201
bool has_exceptions() const
Check if the current binary has exceptions.
Definition PE/Binary.hpp:317
it_delay_imports delay_imports()
Return an iterator over the binary's delay imports.
Definition PE/Binary.hpp:639
it_const_symbols symbols() const
Definition PE/Binary.hpp:403
const RichHeader * rich_header() const
Definition PE/Binary.hpp:595
ref_iterator< exceptions_t &, ExceptionInfo * > it_exceptions
Iterator that outputs ExceptionInfo&.
Definition PE/Binary.hpp:154
bool is_reproducible_build() const
Check if the current binary is reproducible build, replacing timestamps by a compile hash.
uint64_t virtual_size() const override
Compute the binary's virtual size. It should match OptionalHeader::sizeof_image.
std::unique_ptr< Builder > write(const std::string &filename, const Builder::config_t &config)
Reconstruct the binary object with the given configuration and write it in filename.
DataDirectory * debug_dir()
Return the data directory associated with the debug table.
Definition PE/Binary.hpp:821
uint64_t va_to_offset(uint64_t VA) const
Convert the absolute virtual address into an offset.
Definition PE/Binary.hpp:176
std::vector< std::unique_ptr< DataDirectory > > data_directories_t
Internal container for storing PE's DataDirectory.
Definition PE/Binary.hpp:74
const DataDirectory * relocation_dir() const
Definition PE/Binary.hpp:816
Binary * nested_pe_binary()
Definition PE/Binary.hpp:921
DosHeader & dos_header()
Return a reference to the PE::DosHeader object.
Definition PE/Binary.hpp:229
friend class Parser
Definition PE/Binary.hpp:59
Import & add_import(const std::string &name, int32_t pos=-1)
Add an imported library (i.e. DLL) to the binary.
Definition PE/Binary.hpp:668
it_const_relocations relocations() const
Definition PE/Binary.hpp:492
const Section * section_from_rva(uint64_t virtual_address) const
DataDirectory * iat_dir()
Return the data directory associated with the IAT.
Definition PE/Binary.hpp:848
DataDirectory * cert_dir()
Return the data directory associated with the certificate table (authenticode).
Definition PE/Binary.hpp:803
bool has_nx() const override
Check if the binary uses NX protection.
Definition PE/Binary.hpp:759
span< const uint8_t > dos_stub() const
Return the DOS stub content.
Definition PE/Binary.hpp:577
const COFF::String * find_coff_string(uint32_t offset) const
Definition PE/Binary.hpp:428
Header & header()
Return a reference to the PE::Header object.
Definition PE/Binary.hpp:238
it_relocations relocations()
Return an iterator over the PE's Relocation.
Definition PE/Binary.hpp:488
uint64_t imagebase() const override
Return binary's imagebase. 0 if not relevant.
Definition PE/Binary.hpp:194
bool has_configuration() const
Check if the current binary has a load configuration.
Definition PE/Binary.hpp:337
const CodeViewPDB * codeview_pdb() const
Return the CodeViewPDB object if present.
const TLS * tls() const
Definition PE/Binary.hpp:275
ResourceNode * resources()
Return resources as a tree or a nullptr if there is no resources.
Definition PE/Binary.hpp:433
ResourceNode * set_resources(const ResourceNode &root)
Change or set the current resource tree with the new one provided in parameter.
bool has(DataDirectory::TYPES type) const
Check if the current binary has the given DataDirectory::TYPES.
Definition PE/Binary.hpp:521
LoadConfiguration * load_configuration()
Definition PE/Binary.hpp:558
uint32_t sizeof_headers() const
Compute the size of all the headers.
const_ref_iterator< const debug_entries_t &, const Debug * > it_const_debug_entries
Iterator that outputs const Debug&.
Definition PE/Binary.hpp:119
bool remove_debug(const Debug &entry)
Remove a specific debug entry.
DataDirectory * load_config_dir()
Return the data directory associated with the load config.
Definition PE/Binary.hpp:839
const Binary * nested_pe_binary() const
If the current binary contains dynamic relocations (e.g. LIEF::PE::DynamicFixupARM64X),...
Definition PE/Binary.hpp:917
std::vector< std::unique_ptr< Debug > > debug_entries_t
Internal container for storing Debug information.
Definition PE/Binary.hpp:113
Import * get_import(const std::string &import_name)
Return the Import matching the provided name (case sensitive).
Definition PE/Binary.hpp:619
std::unique_ptr< Builder > write(const std::string &filename)
Reconstruct the binary object and write the raw PE in filename.
Definition PE/Binary.hpp:689
it_strings_table coff_string_table()
Definition PE/Binary.hpp:412
it_const_signatures signatures() const
Return an iterator over the Signature object(s) if the binary is signed.
Definition PE/Binary.hpp:348
it_debug_entries debug()
Return an iterator over the Debug entries.
Definition PE/Binary.hpp:526
it_const_sections sections() const
Definition PE/Binary.hpp:224
it_const_strings_table coff_string_table() const
Iterator over the strings located in the COFF string table.
Definition PE/Binary.hpp:408
ref_iterator< imports_t &, Import * > it_imports
Iterator that outputs Import&.
Definition PE/Binary.hpp:97
bool has_delay_import(const std::string &import_name) const
True if the binary delay-imports the given library name
Definition PE/Binary.hpp:660
bool has_imports() const
Check if the current binary contains imports.
Definition PE/Binary.hpp:293
ExceptionInfo * find_exception_at(uint32_t rva)
Try to find the exception info at the given RVA.
void remove(const Section &section, bool clear=false)
Remove the given section.
const Header & header() const
Definition PE/Binary.hpp:242
const DataDirectory * cert_dir() const
Definition PE/Binary.hpp:807
it_data_directories data_directories()
Return an iterator over the DataDirectory present in the Binary.
Definition PE/Binary.hpp:503
it_sections sections()
Return an iterator over the PE's Section.
Definition PE/Binary.hpp:220
void remove_all_imports()
Remove all libraries in the binary.
Definition PE/Binary.hpp:684
Export * get_export()
Return the Export object.
Definition PE/Binary.hpp:388
span< uint8_t > dos_stub()
Definition PE/Binary.hpp:581
bool has_import(const std::string &import_name) const
True if the binary imports the given library name
Definition PE/Binary.hpp:629
DataDirectory * import_dir()
Return the data directory associated with the import table.
Definition PE/Binary.hpp:775
ref_iterator< delay_imports_t &, DelayImport * > it_delay_imports
Iterator that outputs DelayImport&.
Definition PE/Binary.hpp:106
Relocation & add_relocation(const Relocation &relocation)
Add a new PE Relocation.
const_ref_iterator< const exceptions_t &, const ExceptionInfo * > it_const_exceptions
Iterator that outputs const ExceptionInfo&.
Definition PE/Binary.hpp:157
Section * get_section(const std::string &name)
Return binary's section from its name. If the section can't be found, return a nullptr.
Definition PE/Binary.hpp:456
RichHeader * rich_header()
Return a reference to the RichHeader object.
Definition PE/Binary.hpp:591
const DosHeader & dos_header() const
Definition PE/Binary.hpp:233
CodeView PDB specialization.
Definition CodeViewPDB.hpp:37
Class that represents a PE data directory entry.
Definition DataDirectory.hpp:42
TYPES
Definition DataDirectory.hpp:51
@ EXPORT_TABLE
Definition DataDirectory.hpp:52
@ DELAY_IMPORT_DESCRIPTOR
Definition DataDirectory.hpp:65
@ RESOURCE_TABLE
Definition DataDirectory.hpp:54
@ BASE_RELOCATION_TABLE
Definition DataDirectory.hpp:57
@ EXCEPTION_TABLE
Definition DataDirectory.hpp:55
@ IAT
Definition DataDirectory.hpp:64
@ LOAD_CONFIG_TABLE
Definition DataDirectory.hpp:62
@ CERTIFICATE_TABLE
Definition DataDirectory.hpp:56
@ DEBUG_DIR
Definition DataDirectory.hpp:58
@ IMPORT_TABLE
Definition DataDirectory.hpp:53
@ TLS_TABLE
Definition DataDirectory.hpp:61
This class represents a generic entry in the debug data directory. For known types,...
Definition debug/Debug.hpp:40
Class that represents a PE delayed import.
Definition DelayImport.hpp:38
Class which represents the DosHeader, the first structure present at the beginning of a PE file.
Definition DosHeader.hpp:38
This class is the base class for any exception or runtime function entry.
Definition ExceptionInfo.hpp:33
Class which represents a PE Export.
Definition Export.hpp:41
This factory is used to create PE from scratch.
Definition Factory.hpp:29
Class that represents the PE header (which follows the DosHeader).
Definition PE/Header.hpp:36
Class that represents a PE import.
Definition Import.hpp:41
This class represents the load configuration data associated with the IMAGE_LOAD_CONFIG_DIRECTORY.
Definition LoadConfiguration.hpp:49
Class which represents the PE OptionalHeader structure.
Definition OptionalHeader.hpp:43
@ DYNAMIC_BASE
DLL can be relocated at load time.
Definition OptionalHeader.hpp:53
@ NX_COMPAT
Image is NX compatible.
Definition OptionalHeader.hpp:59
Main interface to parse PE binaries. In particular, the static Parser::parse functions should be used...
Definition PE/Parser.hpp:53
Class which represents the Base Relocation Block We usually find this structure in the ....
Definition PE/Relocation.hpp:43
Class which represents a Data Node in the PE resources tree.
Definition ResourceData.hpp:35
Definition ResourceDirectory.hpp:35
Class which represents a Node in the resource tree.
Definition ResourceNode.hpp:46
Class which represents the not-so-documented rich header.
Definition RichHeader.hpp:37
Class which represents a PE section.
Definition PE/Section.hpp:47
Main interface for the PKCS #7 signature scheme.
Definition Signature.hpp:42
VERIFICATION_CHECKS
Flags to tweak the verification process of the signature.
Definition Signature.hpp:98
@ DEFAULT
Default behavior that tries to follow the Microsoft verification process as close as possible.
Definition Signature.hpp:101
VERIFICATION_FLAGS
Flags returned by the verification functions.
Definition Signature.hpp:72
Class which represents the PE Thread Local Storage.
Definition TLS.hpp:44
Definition Visitor.hpp:212
Iterator which returns reference on container's values.
Definition iterators.hpp:47
Wrapper that contains an Object (T) or an error.
Definition errors.hpp:79
#define LIEF_LIFETIMEBOUND
Definition compiler_attributes.hpp:72
Namespace related to the LIEF's PE module.
Definition Abstract/Header.hpp:32
ALGORITHMS
Cryptography algorithms.
Definition PE/enums.hpp:28
PE_TYPE
Definition PE/enums.hpp:22
tcb::span< ElementType, Extent > span
Definition span.hpp:22
ref_iterator< CT, U, typename decay_t< CT >::const_iterator > const_ref_iterator
Iterator which returns a const ref on container's values.
Definition iterators.hpp:316
This structure is used to configure the build operation.
Definition PE/Builder.hpp:53
#define LIEF_API
Definition visibility.h:45
#define LIEF_LOCAL
Definition visibility.h:46