> For the complete documentation index, see [llms.txt](https://cyber-reaper.gitbook.io/my-malware-analysis-guide/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cyber-reaper.gitbook.io/my-malware-analysis-guide/guide/basic-static-analysis/import-address-table.md).

# Import Address Table

Import Address Table (**IAT**) is an important data structure in Windows executables located in `.rdata` section that contains pointers and functions that the executable depends on. Read more about IAT [here](https://www.bordergate.co.uk/import-address-tables/)

We will be discovering this part of the **Portable Executable** (PE) using a tool called [PEView](http://wjradburn.com/software).

First you need to import the executable into the tool to be able to read the metadata and the information that is needed to execute the program or the malware you are analyzing.

In the image below is an example of what the **IAT** looks like when you inspect it, here we have several suspicious imports like the import of `SHELL32.dll`&#x20;

To fully understand how the IAT is that important, check the next section that discuss the Windows API

<figure><img src="https://3687673605-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FIL0b8wPkvjYvwtuOPCCx%2Fuploads%2F6m50aGKf7fLemqpHXnjG%2Fimage.png?alt=media&amp;token=e3f155c0-f453-49dc-9372-6352bf6caaae" alt=""><figcaption></figcaption></figure>
