Deterministic Adversarial PE Testing for Real‑World Loader Correctness
PAAX exposes the exact PE edge‑cases that Windows tolerates but analysis tools mishandle. A curated, reproducible adversarial corpus designed to reveal loader blind spots in reverse‑engineering platforms, DFIR pipelines, and AV/EDR engines.
Your tools don’t see binaries the way Windows does
Real‑world binaries are not clean PE files. Packers, custom loaders, and malware staging chains routinely produce malformed‑but‑valid structures that Windows happily maps, but analysis tools mishandle, misinterpret, or crash on.
This mismatch between Windows semantics and tool assumptions is where:
- silent misanalysis happens
- detection pipelines fail
- DFIR investigations derail
- attackers hide
What PAAX is
PAAX is a curated, taxonomy‑driven suite of adversarial PE fixtures designed to:
- model real packer and loader behaviours.
- stress Windows-aligned loader semantics, not random fuzz artefacts.
- stay aligned with Windows’ permissive mapping model.
- remain fully deterministic and reproducible.
Each fixture isolates a single structural anomaly, classified under the PAAX taxonomy (e.g. VRD‑I, STI‑A, LPM‑3), so you can pinpoint exactly what breaks and why.
Proven impact
A minimal PAAX fixture revealed a loader–tool divergence in Ghidra 12.1:
- Windows mapped the PE as a data image.
- Other independent parsers warned and continued.
- Ghidra crashed with an uncaught
IndexOutOfBoundsException.
After the adversarial context was explained, Ghidra maintainers:
- accepted the issue.
- scheduled it for the 12.2 milestone.
- implemented a fix aligning with Windows semantics.
Who PAAX is for
DFIR & Threat Intel
- Reliable disassembly under adversarial conditions.
- Fewer tool crashes mid‑incident.
- Cross‑tool behavioural clarity.
AV/EDR & Sandbox Vendors
- Stronger detection under malformed-but-valid PEs.
- More reliable feature extraction and unpacking.
- CI/CD regression safety against 1000+ anomalies.
RE Tool Vendors
- Loader correctness aligned with Windows.
- Cross‑tool behavioural benchmarking.
- Early detection of loader regressions.
How PAAX fits into your workflow
- Deterministic fixtures: every anomaly is intentional and explainable.
- Cross‑tool mapping: compare Windows, Ghidra, IDA, Binary Ninja, r2, and more.
- Regression harness: prevent loader regressions before release.
- Custom anomaly design: target your proprietary loader's exact code paths.
Pricing overview
Tiers for research teams, vendors, and high‑assurance environments.
- PAAX Core: curated corpus + annual updates for small teams.
- PAAX Enterprise: full anomaly set, cross‑tool maps, CI/CD harness.
- PAAX Enterprise+: ongoing hardening program with unlimited custom anomaly design, support and workshops.