Aug. 31, 2023, 7 p.m. | Dr Josh Stroschein

Dr Josh Stroschein www.youtube.com

In this video, we'll explore the concept of a forwarded export in a PE file. I'll walk you through what they are, how to identify them and how they are structured in a PE file. Finally, we will explore a sample program to see the final forwarded export function address.

00:00 Introduction
01:11 Looking at Kernel32 for a forwarded export
01:41 What is a forwarded export?
02:00 Identifying a forwarded export in 010 Editor
03:41 Navigating AddressOfNameOrdinals array
05:10 Navigating …

address concept export exports file function identify introduction program sample video

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States