How 7-Zip Extracts Resources from PE Files

7-Zip can open Windows Portable Executable (PE) files—such as .exe, .dll, and .sys—as standard archives, allowing users to inspect and extract embedded resources. Rather than executing the binary, 7-Zip treats the file as a structured container. By parsing the PE headers, locating the .rsrc (resource) section, traversing the hierarchical resource tree, and converting raw byte streams into standalone file formats, 7-Zip exposes icons, bitmaps, strings, manifests, and packaged secondary payloads directly to the user.

Parsing the PE Header and Sections

Every 32-bit and 64-bit Windows binary adheres to the Portable Executable format. When 7-Zip opens an executable, it bypasses code execution and inspects the binary data directly:

  1. DOS and PE Headers: 7-Zip reads the initial IMAGE_DOS_HEADER to find the e_lfanew pointer, which leads to the IMAGE_NT_HEADERS.
  2. Optional Header Data Directories: Within the NT headers, 7-Zip reads the Data Directory array. Index 2 points specifically to the Resource Table (IMAGE_DIRECTORY_ENTRY_RESOURCE), providing its Relative Virtual Address (RVA) and size.
  3. Section Mapping: Executables are divided into sections (such as .text, .data, and .rsrc). 7-Zip maps the RVA of the resource table to a physical raw file offset by referencing the IMAGE_SECTION_HEADER for the .rsrc section.

Traversing the Resource Directory Tree

Windows organizes the .rsrc section as a multi-level tree structure represented by IMAGE_RESOURCE_DIRECTORY tables. 7-Zip parses this structure down through three standard levels:

  1. Level 1 (Type): Defines the category of the resource. Standard types are defined by integer IDs or strings (e.g., RT_ICON [3], RT_BITMAP [2], RT_DIALOG [5], RT_MANIFEST [24], RT_RCDATA [10]). 7-Zip uses these types to categorize items or map them into subfolders.
  2. Level 2 (Name/ID): Identifies specific resource instances within a type (e.g., Resource ID 101 or a custom string name).
  3. Level 3 (Language): Accommodates localization, designating the language and sublanguage (e.g., US English: 0x0409).

At the leaf of each branch sits an IMAGE_RESOURCE_DATA_ENTRY. This structure holds the RVA of the raw data, the exact byte size of the resource, and the code page.

Resolving Offsets and Synthesizing File Headers

Once 7-Zip navigates to a leaf node, it converts the resource RVA into a physical file offset and extracts the raw bytes. However, PE resources often lack the file headers required to exist as valid standalone files on disk. 7-Zip bridges this gap programmatically:

  • Icons and Cursors: In a PE file, icon groups (RT_GROUP_ICON) store directory information, while the actual icon frames (RT_ICON) are stored separately without standard .ico file headers. 7-Zip reads the group descriptor, gathers the corresponding image frames, constructs a valid 6-byte ICONDIR header and ICONDIRENTRY structures, and bundles them with the raw bitmap or PNG data to output a fully functional .ico file.
  • Bitmaps (RT_BITMAP): Windows stores bitmaps internally without the standard 14-byte BITMAPFILEHEADER. 7-Zip synthesizes this header, calculates the correct file offsets, and prepends it to the embedded BITMAPINFOHEADER and pixel data to produce standard .bmp files.
  • Manifests and Raw Data (RT_MANIFEST, RT_RCDATA): Manifests are saved as standard .xml or .manifest text files, while arbitrary binary resources (RT_RCDATA) are extracted as generic binary streams.

Handling Installer Payloads and Overlays

In addition to standard Windows API resources, many executables act as setup wrappers (such as NSIS, Inno Setup, or custom self-extracting zip archives).

7-Zip includes dedicated parsers for known installer formats. If an installer embeds a compressed archive within RT_RCDATA, or if data is appended to the very end of the PE file as an "overlay" (bytes located past the declared end of all PE sections), 7-Zip scans for signature headers. Upon detecting an embedded container format, it unpacks the payload as an inner archive rather than displaying merely the compiled Windows interface resources.