erocarrera / pefileView external linksLinks
pefile is a Python module to read and work with PE (Portable Executable) files
☆2,017Updated this week
Alternatives and similar repositories for pefile
Users that are interested in pefile are comparing it to the libraries listed below
Sorting:
- FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.☆3,877Feb 3, 2026Updated last week
- Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-mem…☆3,553Oct 31, 2025Updated 3 months ago
- LIEF - Library to Instrument Executable Formats (C++, Python, Rust)☆5,272Feb 3, 2026Updated last week
- A static analyzer for PE executables.☆1,104Jan 30, 2026Updated 2 weeks ago
- Reverse engineering framework in Python☆3,818Jan 26, 2025Updated last year
- Triton is a dynamic binary analysis library. Build your own program analysis tools, automate your reverse engineering, perform software v…☆4,049Dec 2, 2025Updated 2 months ago
- IDA Pro utilities from FLARE team☆2,435Oct 29, 2024Updated last year
- Repository of yara rules☆4,697Apr 17, 2024Updated last year
- A list of IDA Plugins☆3,805May 31, 2024Updated last year
- A community driven collection of IDA FLIRT signature files☆1,328Sep 3, 2021Updated 4 years ago
- Principled, lightweight C/C++ PE parser☆886Jan 12, 2026Updated last month
- Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.☆6,849Feb 1, 2026Updated 2 weeks ago
- Noriben - Portable, Simple, Malware Analysis Sandbox☆1,229Aug 7, 2025Updated 6 months ago
- Diaphora, the most advanced Free and Open Source program diffing tool.☆4,177Nov 24, 2024Updated last year
- ☆988Jan 16, 2026Updated 3 weeks ago
- A powerful and user-friendly binary analysis platform!☆8,484Updated this week
- Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loadi…☆3,224Sep 3, 2022Updated 3 years ago
- Windows kernel and user mode emulation.☆1,841Feb 4, 2026Updated last week
- yarGen is a generator for YARA rules☆1,774Jan 10, 2026Updated last month
- IDA 2016 plugin contest winner! Symbolic Execution just one-click away!☆1,609Jun 11, 2025Updated 8 months ago
- DRAKVUF Black-box Binary Analysis☆1,207Feb 1, 2026Updated last week
- The FLARE team's open-source tool to identify capabilities in executable files.☆5,821Updated this week
- Powerful Disassembler Library For x86/AMD64☆1,324Oct 10, 2023Updated 2 years ago
- Capstone disassembly/disassembler framework for ARM, ARM64 (ARMv8), Alpha, BPF, Ethereum VM, HPPA, LoongArch, M68K, M680X, Mips, MOS65XX,…☆8,545Updated this week
- Hex-Rays Decompiler plugin for better code navigation☆2,601Nov 27, 2025Updated 2 months ago
- IDAPython project for Hex-Ray's IDA Pro☆1,527Dec 24, 2025Updated last month
- Export disassemblies into Protocol Buffers☆1,174Feb 2, 2026Updated last week
- A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl☆1,323Oct 31, 2025Updated 3 months ago
- WinAppDbg Debugger☆478Nov 6, 2025Updated 3 months ago
- The pattern matching swiss knife☆9,408Updated this week
- Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that…☆3,857Jun 21, 2024Updated last year
- oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware a…☆3,280Jan 26, 2026Updated 2 weeks ago
- Defund the Police.☆13,426Jun 7, 2024Updated last year
- An advanced memory forensics framework☆7,963May 16, 2025Updated 8 months ago
- Program for determining types of files for Windows, Linux and MacOS.☆10,229Updated this week
- Windows Object Explorer 64-bit☆1,883Updated this week
- A True Instrumentable Binary Emulation Framework☆5,807Nov 5, 2025Updated 3 months ago
- Set of tools to analyze Windows sandboxes for exposed attack surface.☆2,262Nov 6, 2025Updated 3 months ago
- Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)☆8,747Jan 17, 2026Updated 3 weeks ago