The DOS stub resides between the DOS Header (MZ header) and the NT Header. It typically prints a messages that states “This program cannot be run in DOS mode”
This message may be changed at compile time.
DOS Stub
0001-01-01 pe
The DOS stub resides between the DOS Header (MZ header) and the NT Header. It typically prints a messages that states “This program cannot be run in DOS mode”
This message may be changed at compile time.
Program Database
2024-08-05 pe windows
DOS Header
0001-01-01 pe
Data Directory
0001-01-01 pe
Dynamic Link Library
0001-01-01 pe windows
Export Directory
0001-01-01 pe
Linux Persistence: Modular Software
2025-04-17 DFIR CTF persistence linux persistence apache asterisk
Linux Persistence: Web Shells
2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP
Linux Persistence: Rootkits
2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking
Defanging Linux LKM Rootkits With cleanup_module()
2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit