Skip to content

PPEE (puppy)

A professional PE file explorer and editor for malware analysts, reverse engineers, release engineers and security teams, with a GUI, a scriptable CLI, a Docker image and an MCP server for AI assistants.

Get started CLI reference Use with AI (MCP)

PPEE (pronounced puppy) opens any Portable Executable file (EXE, DLL, SYS, OCX, CPL, EFI and .NET assemblies) and shows every structure in it: headers, sections, all 16 data directories, resources, Authenticode signatures, .NET metadata tables, the Rich header, the embedded manifest, hashes and strings. You can edit almost any field in place and save the result.

Animated tour of PPEE: file information, sections, imports with a regex filter, strings, API call sites and Show Code

Choose how you want to use PPEE

  • Desktop GUI


    A tree of every PE structure, sortable list views, a hex editor, a navigator strip that maps the whole file and similarity alerts. It runs on Windows XP through Windows 11 and on Linux.

    GUI guide

  • Command line


    ppee-cli prints any subset of the file as text or JSON, patches fields with --set and exits non-zero on failure, so it fits into scripts.

    CLI reference

  • Docker


    A small Debian-based image around ppee-cli that respects container CPU limits and runs with a read-only root and no network.

    Docker guide

  • CI/CD


    Gate releases on signatures, ASLR/DEP/CFG flags, unexpected imports or known-bad hashes in GitHub Actions, GitLab, Jenkins or Azure Pipelines.

    CI/CD integration

  • AI assistants (MCP)


    ppee-cli --mcp is a Model Context Protocol server, so Claude and other MCP clients can triage binaries for you.

    MCP guide

  • Runtime analysis


    Build settings, dependencies, source paths, obfuscation and encrypted code in .NET, Go, Rust and NativeAOT binaries, read from their metadata without running them.

    Runtime analysis

  • Walkthroughs


    Real malware, one question at a time: a NativeAOT ransomware, a payload-container DLL, a signed installer, a shellcode loader and 19 shorter walkthroughs. Static only, nothing executed.

    Walkthroughs

  • PE feature reference


    What each structure means, where it is in the GUI, and which CLI switch and JSON key expose it.

    PE features

Feature matrix

Capability GUI CLI Docker MCP tool
DOS / NT / File / Optional headers --headers analyze_pe
Section table --sections analyze_pe
Imports, delay-load and bound imports --imports list_imports
Exports and forwarders --exports list_exports
Resources (type/name/language) --resources analyze_pe
Authenticode signatures --security check_signature
.NET header and streams (metadata tables: GUI) --net analyze_pe
Load Config, CFG and SafeSEH --loadconfig analyze_pe
Rich header and manifest --richheader, --appmanifest analyze_pe
MD5 / SHA / ImpHash / Authentihash / SSDEEP / TLSH --hashes get_hashes
Strings (ASCII, Unicode, URL, registry, suspicious) --strings get_strings
Runtime analysis: .NET, Go, Rust, NativeAOT --analysis analyze_pe
Similarity database --similarity check_similarity
Field editing and saving --set / --save patch_pe (opt-in)
Code analysis: entry-point anomalies, APIs in use, patterns --analysis triage_pe, analyze_pe
Disassembly and cross-references (x86/x64) Code window --disasm, --xrefs, --functions disassemble, get_xrefs, list_functions
Hex view / editor - - -
Navigator strip (file map) - - -
Signature validity (WinVerifyTrust) Windows only Windows only - Windows only

Supported platforms

Platform GUI binary CLI binary Notes
Windows XP SP3 → Windows 11 ppee.exe (Direct3D 9, with a GDI software-rendering fallback) ppee-cli.exe 32-bit static executables that also run on 64-bit Windows and analyze both PE32 and PE32+; no installer, no runtime
Linux x86-64 ppee (GLFW + OpenGL 3) ppee-cli glibc 2.38+
Docker / OCI - ppee-cli image debian:trixie-slim base

Sixty-second tour

ppee sample.exe          # or drag files onto the window

Pick a node in the left tree (for example DIR_ENTRY_IMPORT). Its rows appear in the upper list, and clicking a row fills the lower list. Double-click a value to edit it, then press Ctrl+S to save.

ppee-cli --hashes --imports sample.exe
ppee-cli --json --all sample.exe > sample.json
docker run --rm -v "$PWD:/data:ro" ppee-cli --json --hashes /data/sample.exe
claude_desktop_config.json
{ "mcpServers": { "ppee": { "command": "C:\\Tools\\ppee\\ppee-cli.exe", "args": ["--mcp"] } } }

Then ask: "Is C:\Samples\setup.exe signed, and does it import anything network-related?"

New to PE files?

Start with Quick Start, then read Headers & Sections. Every feature page links to the GUI view, the CLI switch and the JSON key that expose it.