PE import declarations do not prove Windows loading
Separate a declared module name, a finite selected-file match and the operating-system loader decision before treating an import inventory as a deployment diagnosis.
A dependency question contains several different questions
A developer can need the DLL names declared by a native file before deciding which files to collect. Dmitry’s request explicitly avoided loading the DLL. That endpoint is useful, but it cannot itself answer whether the operating system will find, trust and execute the program.
A static import records modules and name/ordinal thunks. A finite selected-file comparison adds only a chosen basename and machine declaration. The runtime loader has its own environment and policy. Mixing those layers can turn a correct inventory into an incorrect deployment conclusion.
Follow a finite companion-file example
root.exe declares HELPER.DLL. With root.exe alone selected, not-selected describes this selected set. Adding one supported helper.dll with the same machine gives selected-declaration through ASCII case folding. Adding a second HELPER.DLL makes the selection ambiguous; choosing an x64 helper for an x86 root shows a machine mismatch.
Even the unique matching case can still have unsuitable exports, versions, signatures or recursive dependencies. This inventory reads none of those results. The raw declaration and exact source SHA are useful facts to hand to the next investigation.
| Layer | This tool supplies | Remaining question |
|---|---|---|
| PE declaration | Direct/delay module, name/hint/ordinal and raw addresses | What will use the declaration at runtime? |
| Finite selected-file match | Name/machine status and selected indices | Do exports and versions meet runtime requirements? |
| Windows loader | No loader result supplied | Which environment, API-set host, search policy and trust decision apply? |
An API-set name is not an instruction to find a same-name file
API-set contracts use virtual names with operating-system host mappings. A missing same-name selection therefore is not proof of a missing DLL, and a same-spelling selected binary does not replace the OS mapping. The report keeps the declaration rather than silently guessing a host DLL.
Direct imports and delay imports are also distinct declarations within one task. The finite profile accepts legacy VA delay data only in PE32; PE32+ legacy VA refuses atomically. The inventory does not execute a delay-load helper or predict whether a delayed import will ever be invoked.
Make the handoff complete and proportionate
A long module preview or copied summary can omit declarations by design. The complete two-member ZIP carries all JSON source/descriptor/thunk fields and all formula-safe CSV symbol rows; descriptors without symbols remain visible in JSON. Complete data must satisfy all input, structure and32MiB report limits together.
Reusing a long name at many thunks can expand a report far beyond the file size. The producer charges the mandatory JSON/CSV occurrences before retaining more symbols, then measures the final report; this protects the bounded workflow without lowering its admitted limits.
- Use the source SHA and complete ZIP as the reproducible handoff.
- Interpret selected statuses literally; avoid relabeling not-selected as missing or a name match as loaded.
- Keep no-import results and Unsupported profiles explicit instead of substituting guessed imports.
- After error or cancellation, correct the input and run a fresh inventory; no partial ZIP is published.
References
- Native DLL inventory demand: Dmitry, Stack Overflow
First-person need to obtain dependencies without loading the DLL; original question checked2026-10-08, CC BY-SA3.0. No original DLL attached, reproduction or web-tool preference established.
- Microsoft PE/COFF format
Header, section, import/delay tables and reserved bits; format reference supports correctness, not demand.
- Microsoft API-set loader operation
Virtual contracts and runtime host mapping differ from basename matching; this tool does not perform that mapping.
- Microsoft DLL search order
Loader context and search policy remain outside static file declarations.
Tools in this category
Expand a tool to see its steps, options and supported formats, then open its workspace.
Inspect native PE import declarationsRead direct and delay imports from local x86 PE32 or x64 PE32+ files, keep name/ordinal and source hashes, and export complete JSON plus formula-safe CSV in one ZIP.
Inspect import declarations without loading a DLL or executing an EXE. Selected-file matches compare only finite names and machine declarations; use the complete ZIP when deciding what to investigate next.
Steps
- Select the local native PE files whose import declarations you need; original bytes remain unchanged.
- Run the inventory and inspect direct/delay modules, symbol counts and finite selected-file statuses.
- Download pe-imports.zip; read every JSON declaration and CSV symbol row with its source SHA.
- Use suitable authorized Windows tooling for actual loader, API-set, export or trust questions.
Capabilities and limits
- 1–100 local files, at most20MiB each and80MiB together;1–96 sections per file,10,000 import descriptors and100,000 imported symbols across the set. Every budget applies together.
- Only native x86 PE32 and x64 PE32+ with uniquely file-backed RVA tables. CLR, other machines and bound-only imports without an original lookup table are unsupported. Delay imports allow PE32 RVA/legacy VA and PE32+ RVA only; PE32+ legacy VA is unsupported.
- Imported module/symbol names are printable ASCII ASCIIZ, at most4,096 bytes. Selected basenames must be printable ASCII without path separators. Named RVA thunks use31 bits; ordinal reserved bits, header/section boundaries, table terminators and directory declarations are checked.
- Matching uses only ASCII case folding among selected basenames. not-selected means no same-name file was selected; selected-declaration means a unique selected name/machine declaration matches. Ambiguous names and machine mismatches are explicit. These states do not establish exports, trust, DLL availability or Windows loading.
- API-set names are virtual OS contracts, without a guaranteed same-name disk DLL. No OS search, API-set host mapping, recursive dependency resolution, file fetch, DLL loading, code execution or signature/trust audit occurs.
- pe-imports.zip contains exactly pe-imports.json and pe-imports.csv. Complete report bytes together allow32MiB; the fixed two-member STORE headers add232 bytes. The34MiB ZIP guard is dominated by that report budget, not another reachable report-size axis. Reused long names are charged before report expansion.
- JSON retains every source SHA/byte count, section, descriptor, raw thunk, name/hint/ordinal and selected-file status. CSV has every imported-symbol row; descriptors without symbols and files with no imports remain explicit in JSON. CSV formula prefixes are neutralized without changing raw JSON names.
- The interface previews the first200 module declarations, long cells first2,000 UTF-16 units. Copy gives full JSON up to20,000 UTF-16 units and an explicit summary above it; complete JSON/CSV always remain in ZIP. Malformed, unsupported, over-limit or cancelled work publishes no partial ZIP.