Daniel Roberson
  • Posts
  • About
  • Notes
  • Projects
  • Time
  • Posts
    About
    Notes
    Projects
    Time

Process Environment Block

0001-01-01 windows

The Process Environment Block (PEB) is a data structure of the Windows NT operating system family containing data structures including global context, startup parameters, information used by the program loader, the program’s base address, and other data.

The structures related to PEB is not completely documented by Microsoft and may be subject to change.

https://en.wikipedia.org/wiki/Process_Environment_Block


Links to this note

  • metasploit shellcode grows up: encrypted and authenticated C shells-pace2019

Relevant Topics

Program Database

2024-08-05 pe windows

Dynamic Link Library

0001-01-01 pe windows

LoadLibrary

0001-01-01 winapi windows

PEBear

0001-01-01 malwareanalysis reversing pe windows

Portable Executable

0001-01-01 pe windows


Recent Posts

Linux Persistence: Modular Software

2025-04-17 DFIR CTF persistence linux persistence apache asterisk

Linux Persistence: Web Shells

2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP

Linux Persistence: Rootkits

2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking

Linux Persistence: Processes

2025-04-11 DFIR persistence processes linux persistence processes

Defanging Linux LKM Rootkits With cleanup_module()

2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit


Home

About

Notes

Projects

Time

© All rights reserved. Powered by Hugo and Erblog.