Uninformed: Informative Information for the Uninformed

Vol 4» 2006.Jun


Exception Directory Enumeration

Given the explanation of the Exception Directory found within PE32+ images and its application to the exception dispatching process, it can be seen that x64 binaries have a lot of useful meta-information stored within them. Given that this information is just sitting there waiting to be used, it makes sense to try to take advantage of it in ways that make it possible to better annotate or understand an x64 binary. The following subsections will describe different things that can be discovered by digging deeper into the contents of the exception directory.



Subsections