drop a packed or dumped pe · reconstruct iat · resolve api hashes · identify dynamically loaded functions · rebuild import table · runs locally
drop PE / unpacked dump — parsing never executes code