Jump to content
Sign in to follow this  
top10

PPEE (puppy) 1.08

Recommended Posts

top10

PPEE (puppy) is a Professional PE file Explorer for
reversers, malware researchers and those who want to statically inspect PE files in more details

Features

Puppy is robust against malformed and crafted PE files which makes it handy for reversers, malware researchers and those who want to inspect PE files in more details. All directories in a PE file including Export, Import, Resource, Exception, Certificate(Relies on Windows API), Base Relocation, Debug, TLS, Load Config, Bound Import, IAT, Delay Import and CLR are supported.

  • Both PE32 and PE64 support
  • Virustotal and OPSWAT's Metadefender query report
  • Statically analyze windows native and .Net executables
  • Robust Parsing of exe, dll, sys, scr, drv, cpl, ocx and more
  • Edit almost every data structure
  • Easily dump sections, resources and .Net assembly directories
  • Entropy and MD5 calculation of the sections and resource items
  • View strings including URL, Registry, Suspicious, ... embedded in files
  • Extract artifacts remained in PE file
  • Anomaly detection
  • Right-click for Copy, Search in web, Whois and dump
  • Built in hex editor
  • Explorer context menu integration
  • Descriptive information for data members
  • Refresh, Save and Save as menu commands
  • Drag and drop support
  • List view columns can sort data in an appropriate way
  • Open file from command line
  • Checksum validation
  • Plugin enabled
01-FileHeader.png

Descriptive information

02-OptionalHeader.png

PE32+ Optional Header

03-DataDirs.png

Grayed out Entries

04-SectionHeader.png

High Entropy Malformed Section

05-Exports.png

Export Directory

06-DriverImports.png

PE32+ Import Directory

07-EmbeddedBinary.png

Embedded PE in Resource

08-HighEntropyLocaleResource.png

High Entropy Locale Resource

09-BrokenSecurity.png

Invalid digital signature

10-Debug.png

Binary compile path and time

11-TLS-Callback.png

Thread Local Storage Data

12-LoadConfig.png

SEH-CFG Handlers

13-BoundImports.png

Bound Imports Directory

14-DelayImports.png

Delay Load Imports

15-.NetDir.png

.Net Assembly Metadata Header

16-vtable.png

.Net VTable Fixups

17-Strings.png

Malicious string used in binary

18-Plugin.png

Virustotal and OPSWAT query

Download

https://www.mzrst.com/puppy/PPEE(puppy) 1.08.zip

  • Like 1
  • Upvote 2

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

×

Important Information

Guidelines