# pe-coff

> Parse the COFF file header of a PE

Latest version **1.0.0** (published 2016-12-19) · MIT license · 0 weekly downloads

## Install

```sh
npm install pe-coff
pnpm add pe-coff
yarn add pe-coff
bun add pe-coff
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.0 |
| Published | 2016-12-19 |
| First published | 2016-12-19 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >=4.0.0 |
| Dependencies | 5 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 3 |
| Author | Vincent Weevers |
| Maintainers | vweevers |
| Keywords | coff, pe, pe-coff, portable-executable, windows |

## Links

- npm: https://www.npmjs.com/package/pe-coff
- Repository: https://github.com/vweevers/pe-coff
- Issues: https://github.com/vweevers/pe-coff/issues
- npm.io page: https://npm.io/package/pe-coff

## Dependencies (5)

- [pe-signature](https://npm.io/package/pe-signature.md) ~1.0.0
- [fs-maybe-open](https://npm.io/package/fs-maybe-open.md) ~1.0.0
- [fs-read-exactly](https://npm.io/package/fs-read-exactly.md) ~1.0.0
- [pe-signature-offset](https://npm.io/package/pe-signature-offset.md) ~1.0.0
- [pe-machine-type-descriptor](https://npm.io/package/pe-machine-type-descriptor.md) ~1.0.0

## Alternatives

- [@opentelemetry/exporter-zipkin](https://npm.io/package/@opentelemetry/exporter-zipkin.md) — 14.8M weekly downloads
- [pusher-js](https://npm.io/package/pusher-js.md) — 2.0M weekly downloads
- [browserify](https://npm.io/package/browserify.md) — 1.7M weekly downloads
- [sqs-consumer](https://npm.io/package/sqs-consumer.md) — 1.7M weekly downloads
- [@sanity/eventsource](https://npm.io/package/@sanity/eventsource.md) — 930.8K weekly downloads

## Recent versions

- 1.0.0 (latest) — 2016-12-19

## README

# pe-coff

**Parse the COFF file header of a [PE](https://en.wikipedia.org/wiki/Portable_Executable). As specified by [Microsoft PE and COFF Specification 9.3](https://download.microsoft.com/download/9/c/5/9c5b2167-8017-4bae-9fde-d599bac8184a/pecoff_v83.docx) <sup>[doc]</sup>, section 3.3.**

[![npm status](http://img.shields.io/npm/v/pe-coff.svg?style=flat-square)](https://www.npmjs.org/package/pe-coff) [![node](https://img.shields.io/node/v/pe-coff.svg?style=flat-square)](https://www.npmjs.org/package/pe-coff) [![Travis build status](https://img.shields.io/travis/vweevers/pe-coff.svg?style=flat-square&label=travis)](http://travis-ci.org/vweevers/pe-coff) [![AppVeyor build status](https://img.shields.io/appveyor/ci/vweevers/pe-coff.svg?style=flat-square&label=appveyor)](https://ci.appveyor.com/project/vweevers/pe-coff) [![Dependency status](https://img.shields.io/david/vweevers/pe-coff.svg?style=flat-square)](https://david-dm.org/vweevers/pe-coff)

## example

```js
const pecoff = require('pe-coff')

pecoff('file.exe', function (err, header, location) {
  console.log(header)
  console.log(location)
})
```

The `header` has these properties:

```json
{
  "machineType": "i386",
  "machineDescription": "Intel 386 or later processors and compatible processors",
  "numberOfSections": 3,
  "timeDateStamp": 1480757919,
  "pointerToSymbolTable": 0,
  "numberOfSymbols": 0,
  "sizeOfOptionalHeader": 224,
  "characteristics": 258
}
```

And `location` contains the offset and length of the header in bytes:

```json
{
  "offset": 132,
  "length": 20
}
```

## `pecoff(mixed, [limit], callback)`

Where `mixed` is either a filename or a file descriptor. Use `limit` (the number of bytes to read) if you only need the first (few) fields:

```js
pecoff('file.exe', pecoff.NUMBER_OF_SECTIONS, function (err, header) {
  // Will have machineType, machineDescription, numberOfSections
  console.log(header)
})

pecoff('file.exe', pecoff.MACHINE_TYPE, function (err, header) {
  // Will have machineType, machineDescription
  console.log(header)
})
```

## related

- [pe-signature](https://github.com/vweevers/pe-signature)
- [pe-signature-offset](https://github.com/vweevers/pe-signature-offset)
- [pe-machine-type-descriptor](https://github.com/vweevers/pe-machine-type-descriptor])

## install

With [npm](https://npmjs.org) do:

```
npm install pe-coff
```

## license

[MIT](http://opensource.org/licenses/MIT) © Vincent Weevers

---
_Source: https://npm.io/package/pe-coff · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
