Skip to content

Security Scan of exe made with SEA #127

Description

@TeoBotta90

Hi, recently our software was scanned by Spectra Assure and they found the following issue with our SEA executable: 'Win64.Format.Malformed' of type 'PE+/Exe'. I've contacted them via email and this is their answer: "The export table overlaps with executable headers. This is commonly abused by malware to avoid detection from security solutions. The findings are a true positive. Files that are properly compiled do not exhibit this kind of behavior". Could you please check? Otherwise, the SEA executables are not production-ready. Thank you

Activity

  1. GabenGar commented on Sep 16, 2026

    @GabenGar

    The docs for the hottest version of 26 say it's in active development. Where did you get the idea it's anywhere prod-ready?

  2. TeoBotta90 commented on Sep 16, 2026

    @TeoBotta90
    Author

    Fair point that the docs state SEA is still in active development, but identifying real-world blockers like PE header malformations or AV heuristic flags is precisely the point of early adoption and testing.
    ​"Production-ready" or not, an overlapping export table is a technical issue in the post-injection binary structure that triggers AV/EDR alerts (Win64.Format.Malformed). Addressing these reports is what actually gets experimental features closer to stability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions