PPEE (puppy) is a Professional PE file Explorer for
reversers, malware researchers and those who want to statically inspect PE files in more details
PPEE is free and tries to be small, fast, nimble and
friendly as your puppy!
Features
PPEE is robust against malformed and crafted PE files which makes it handy
for reversers, malware researchers and those who want to inspect PE files in more details.
All directories in a PE file including Export, Import, Resource, Exception, Certificate(
- Very fast malware static analysis tool
- Both PE32 and PE64 support
- Clustering/similarity engine — similar binaries detected via locally stored hashes and grouped by color
- Multi-file support with flexible tabs
- Parse and edit .Net (CLR) assemblies
- ARM64 exception directory support
- Extended debug directory parsing/editing (FPO, POGO, PDB checksum, embedded portable PDB, and more)
- TLS callback list
- Filter/search boxes for listviews
- Application manifest support in treeview
- Examine Yara rules against opened file
- Virustotal and OPSWAT's Metadefender query report
- Statically analyze windows native and .Net executables
- Robust Parsing of exe, dll, sys, scr, drv, cpl, ocx and more
- Parse Rich Header
- Parse Safe SEH, Control Flow Guard Functions, Enclave Configuration and Volatile information in load config directory
- Edit almost every data structure
- Easily dump sections, resources and .Net assembly directories
- Entropy and MD5 calculation of the sections and resource items
- Entropy, SSDEEP, TLSH, CRC32, ImpHash, MD5, SHA1, SHA256 and Authentihash calculation of the files
- View strings including URL, Registry, Suspicious, ... embedded in files
- Resolve ordinal to name in imported APIs
- Demangle (undecorate) mangled import/export APIs
- Detect common resource types
- Extract artifacts remained in PE file
- Anomaly detection
- Right-click for Copy, Search in web, Whois and dump
- Easily access recent opened files
- Built in hex editor
- Explorer context menu integration
- Descriptive information for data structures
- Refresh, Save and Save as menu commands
- Open file by drag and drop
- Sortable list-view columns
- Open file from command line
- Checksum validation
- Plugin enabled
About puppy
There are lots of tools out there for statically analyzing malicious binaries,
but they are ordinary tools for ordinary files.
PPEE is a lightweight yet strong tool for static investigation of suspicious files.
Two companion plugins are also provided. FileInfo, to query the file in the well-known malware repositories and take one-click technical information about the file such as its size, entropy, attributes, hashes, version info and so on. YaraPlugin, to test Yara rules against opened file.
The whole zip file hash:
MD5: D30F19D21A08739CF3C88D4362F2D94F
SHA1: 7E63C6B2066242F3A0ABEA6438D5C4B995503BB6
SHA256: 81973D3DB6806E201EF25DB364BA68575814E73D03CE95564D77EC8B1860FFFF
Size: 1.59 MiB
Current version: 1.15 (2026-08-25)
Previous releases are also available for download:
Contact
For any comments, bug reports or feature request please e-mail me: [email protected]

























