
New releaseJul 18, 2026
TABPE v2026.7
A monthly Windows PE baseline dataset for Cyber security researchers
TABPE
What is TABPE?
TABPE (a combination of TABriz + PE - Tabriz is my hometown, and I named this project after my love for my city) is an open, structured dataset containing information about all PE files (Windows executables) including .exe, .dll, .sys, etc., on clean, fully updated versions of Windows 10 Pro and Windows 11 Pro.
My workflow is as follows:
- I installed Windows and, each month after Microsoft releases its security updates (Patch Tuesday), I tried to update the system.
- In some months, the update was applied exactly on the same day or a few days after Patch Tuesday.
- In other months, due to various reasons (such as internet outages in Iran), I couldn't update on time. In those cases, I manually downloaded and installed the update files (
.msu). - As a result, the exact scan time relative to Patch Tuesday may vary from a few days to a few weeks. However, in the end, all updates released by Microsoft up to the scan date were applied to the system.
The exact start and end time of each scan is recorded in the
pe_files_info.jsonfile under thescan_infosection.
Project Outputs
Each Release provides three main files:
| File | Description |
|---|---|
pe_files_info.json | The main file containing complete information about all PE files (headers, sections, imports, exports, SHA256 hash, security info, LOAD_CONFIG, etc.) |
file_list.txt | Complete list of paths to all PE files in that specific Windows version |
scanner.log | Log of errors and files the scanner could not access (Access Denied) + error |
Sample structure of pe_files_info.json
{
"scan_info": {
"start_time": "2026-06-04T06:21:51-07:00",
"end_time": "2026-06-04T08:09:37-07:00",
"duration": "1h 47m 45s",
"windows_version": {
"os_name": "Windows 11 Pro",
"os_version": "10.0.26100.8457 Build 26100",
"system_type": "x64-based PC",
"version": "24H2",
"last_update": "KB5087054"
},
"total_files": 29377,
"error_files": 12,
"error_files_list": [
{
"id": 7618,
"path": "C:\\Windows\\SysWOW64\\compobj.dll"
},
{
"id": 8561,
"path": "C:\\Windows\\SysWOW64\\ole2disp.dll"
},
{
"id": 8562,
"path": "C:\\Windows\\SysWOW64\\ole2nls.dll"
},
{
"id": 8560,
"path": "C:\\Windows\\SysWOW64\\ole2.dll"
},
{
"id": 8839,
"path": "C:\\Windows\\SysWOW64\\storage.dll"
},
{
"id": 8912,
"path": "C:\\Windows\\SysWOW64\\typelib.dll"
},
{
"id": 28768,
"path": "C:\\Windows\\WinSxS\\x86_microsoft-windows-n..nd-syswow64-payload_31bf3856ad364e35_1.0.26100.1_none_d3b8ff829e6c9bfb\\ole2.dll"
},
{
"id": 28767,
"path": "C:\\Windows\\WinSxS\\x86_microsoft-windows-n..nd-syswow64-payload_31bf3856ad364e35_1.0.26100.1_none_d3b8ff829e6c9bfb\\compobj.dll"
},
{
"id": 28769,
"path": "C:\\Windows\\WinSxS\\x86_microsoft-windows-n..nd-syswow64-payload_31bf3856ad364e35_1.0.26100.1_none_d3b8ff829e6c9bfb\\ole2disp.dll"
},
{
"id": 28770,
"path": "C:\\Windows\\WinSxS\\x86_microsoft-windows-n..nd-syswow64-payload_31bf3856ad364e35_1.0.26100.1_none_d3b8ff829e6c9bfb\\ole2nls.dll"
},
{
"id": 28772,
"path": "C:\\Windows\\WinSxS\\x86_microsoft-windows-n..nd-syswow64-payload_31bf3856ad364e35_1.0.26100.1_none_d3b8ff829e6c9bfb\\typelib.dll"
},
{
"id": 28771,
"path": "C:\\Windows\\WinSxS\\x86_microsoft-windows-n..nd-syswow64-payload_31bf3856ad364e35_1.0.26100.1_none_d3b8ff829e6c9bfb\\storage.dll"
}
]
},
"pe_files": [
{
"id": 1,
"filename": "msdaosp.dll",
"path": "C:\\Program Files\\Common Files\\System\\Ole DB\\msdaosp.dll",
"sha256": "38390b62e81fd3381d6ea2d50c5e35ff93370e70122326c0cb8de53f9f9085d0",
"file_type": "dll",
"has_rich_header": "YES",
"machine": "AMD64",
"time_date_stamp": "2010-06-03 08:46:58 UTC",
"characteristics": [
"EXECUTABLE_IMAGE",
"LARGE_ADDRESS_AWARE",
"UP_SYSTEM_ONLY"
],
"magic": "PE32+",
"major_linker_version": 14,
"minor_linker_version": 38,
"major_os_version": 10,
"minor_os_version": 0,
"major_image_version": 10,
"minor_image_version": 0,
"major_subsystem_version": 10,
"minor_subsystem_version": 0,
"checksum": 188850,
"subsystem": "WINDOWS_GUI",
"dll_characteristics": [
"DYNAMIC_BASE",
"GUARD_CF",
"HIGH_ENTROPY_VA",
"NX_COMPAT"
],
"data_directories": [
"EXPORT_TABLE",
"IMPORT_TABLE",
"RESOURCE_TABLE",
"EXCEPTION_TABLE",
"BASE_RELOCATION_TABLE",
"DEBUG",
"LOAD_CONFIG_TABLE",
"IAT"
],
"sections": [
{
"name": ".text",
"characteristics": [
"CNT_CODE",
"MEM_EXECUTE",
"MEM_SHARED"
]
},
{
"name": "fothk",
"characteristics": [
"CNT_CODE",
"MEM_EXECUTE",
"MEM_SHARED"
]
},
{
"name": ".rdata",
"characteristics": [
"CNT_INITIALIZED_DATA",
"MEM_EXECUTE"
]
},
{
"name": ".data",
"characteristics": [
"CNT_INITIALIZED_DATA",
"MEM_EXECUTE",
"MEM_READ"
]
},
{
"name": ".pdata",
"characteristics": [
"CNT_INITIALIZED_DATA",
"MEM_EXECUTE"
]
},
{
"name": ".rsrc",
"characteristics": [
"CNT_INITIALIZED_DATA",
"MEM_EXECUTE"
]
},
{
"name": ".reloc",
"characteristics": [
"CNT_INITIALIZED_DATA",
"LNK_NRELOC_OVFL",
"MEM_EXECUTE"
]
}
],
"exports": [
"DllCanUnloadNow",
"DllGetClassObject",
"DllMain",
"DllRegisterServer",
"DllUnregisterServer"
],
"imports": [
{
"dll_name": "ADVAPI32.DLL",
"functions": [
"RegCloseKey",
"RegOpenKeyExW",
"RegQueryValueExW"
]
},
{
"dll_name": "KERNEL32.DLL",
"functions": [