
Object Pascal (Delphi) library for parsing, mapping, loading, and dumping Windows PE files, with relocations, imports, TLS, and remote process memory reading.
NativePe is a Windows Portable Executable library written in Object Pascal for Delphi.
The project focuses on PE parsing, mapping, loading, relocation, import and export handling, dumping, process memory reading, and related Windows internals. It supports Win32 and Win64 builds from the same source tree.
NativePe is a research project. It has been tested against a large set of normal, unusual, malformed, and hostile PE files, but it does not claim to handle every possible PE file correctly.
Part of the motivation is personal. I used Delphi around the early 2000s and wanted to revisit low-level Windows development with modern Delphi.
NativePe is also a practical experiment to show that Object Pascal can still be used for PE and Windows internals research.
The NativePe PE-processing core is an Object Pascal port/reimplementation of libpeconv by hasherezade.
The code was rewritten in Object Pascal, but the core module split and many public operations, validation paths, control-flow decisions, fallback rules, diagnostics, and tests were derived from the libpeconv source. NativePe is therefore not a clean-room or independently designed implementation of the libpeconv functionality it ports.
The libpeconv revision used by the current differential harness is commit 0fc25f680e03699d33ef3b2034a6724365f3d1a4.
Thanks to hasherezade for publishing libpeconv. See docs/PROVENANCE.md for the source-level relationship and THIRD-PARTY-NOTICES.md for attribution and license notices.
NativePe is more than a syntax translation of libpeconv. The current project adds NativePe-specific functionality and Delphi/Windows integration around the ported core.
This includes API Set resolution, pluggable WinAPI/NTAPI/direct-syscall memory providers, security-cookie initialization, PE recycling helpers, and related integration code. These parts have no direct source-module counterpart in the pinned libpeconv core.
The repository also contains NativePe-specific Delphi test projects, real-world fixtures, corpus tooling, and Windows integration tests.
More details are in docs/FEATURES.md.
NativePe separates PE logic from selected operating system memory operations through TNativePeMemoryProvider.
The current built-in backends are:
TWinApiMemoryProviderTNtApiMemoryProviderTSyscallMemoryProvider on Win64The existing hook path also keeps its optional UseSyscalls compatibility switch for direct syscall based memory protection.
NativePe uses several test layers:
The documented differential run from September 25, 2026 processed 30,159 identical corpus paths with NativePe and the pinned libpeconv harness. At outcome level, 30,147 paths matched and 12 differed. NativePe recorded no worker crashes in that run; the libpeconv harness recorded six. These results describe this corpus and these harnesses only and do not establish general superiority.
The run was not a benchmark-quality performance run, so its timing data is not used for performance claims. External corpora and malware samples are not distributed with NativePe.
See docs/TESTING.md, docs/CORPUS-RESULTS.md, and docs/LIBPECONV-COMPARISON.md.
NativePe is developed with Delphi 12 Athens.
Open NativePe.groupproj to build the included demo, tests, corpus runner, process dump tool, and real-world test projects.
The main library source is under src. Projects can also use NativePe directly by adding src to the Delphi unit search path and referencing the required NativePe.* units.
Both Win32 and Win64 are supported by the included projects.
The following example maps a PE image, applies relocations, and resolves imports. It does not call the PE entry point.
program PeLoaderMinimal;
{$APPTYPE CONSOLE}
uses
System.SysUtils,
NativePe.BufferUtil,
NativePe.PeLoader;
var
Image: TAlignedBuf;
ImageSize: NativeUInt;
begin
if ParamCount <> 1 then
Halt(1);
Image := LoadPeExecutable(ParamStr(1), ImageSize);
if Image = nil then
Halt(1);
try
Writeln('Loaded at: 0x', IntToHex(NativeUInt(Image), SizeOf(Pointer) * 2));
Writeln('Virtual size: ', ImageSize);
finally
FreePeBuffer(Image, ImageSize);
end;
end.
Add src to the Delphi unit search path and run the program with a PE file as its only argument.
The repository contains several executables and helper scripts. The main entry points are documented in docs/BINARIES.md.
Important: NativePeDemo.exe loads and executes the supplied PE file. Use it only with trusted test files. The corpus runner is designed for static PE processing and does not intentionally execute PE entry points or TLS callbacks.
NativePe is actively used as a research and testing project. APIs and implementation details may still change as new PE edge cases are found.
Extensive testing reduces risk, but it is not proof of complete correctness. Treat untrusted PE files as untrusted input and use appropriate isolation when working with malware.