💾 Binary Forensics

Inspect executables, libraries, WebAssembly modules, and arbitrary binaries as static data, including headers, sections, imports, strings, entropy, anomalies, and raw bytes.

This tool is client-side only. Everything happens in your browser and none of your data is shared.

Drop a binary here or click to choose one PE / EXE / DLL · ELF · Mach-O / Fat · WebAssembly · arbitrary binary files

About This Tool

Binary Forensics is a static binary analysis tool for examining Windows PE files, ELF executables, Mach-O binaries, WebAssembly modules, libraries, and unrecognized binary files. It reads the selected file as inert bytes and does not execute, load, or instantiate the program.

Format-specific parsers expose executable headers, sections, program segments, load commands, imports, exports, memory layout information, and other structures used by operating systems and runtimes. Windows PE analysis also covers data directories, Rich Header records, PDB clues, certificate structures, .NET headers, relocations, TLS data, and recognizable imported API groups.

The entropy view measures byte distribution across the file, while printable-string extraction can reveal paths, URLs, library names, compiler artifacts, messages, and other embedded text. Structural findings flag malformed records or unusual properties without treating them as a malware verdict.

A physical file map and hex inspector provide direct access to offsets and raw bytes. The exported forensic report records the detected format, SHA-256 hash, parsed structures, findings, and extracted strings for later review.