retoolkit
retoolkit copied to clipboard
Add PPEE (puppy)
I recommend adding PPEE (puppy). It is a Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in more detail. Some of the features include:
- Very fast malware static analysis tool
- Both PE32 and PE64 support
- Examine Yara rules against opened file
- Virustotal and OPSWAT's Metadefender query report
- Statically analyze windows native and .Net executables
- Parse Rich Header
- Parse Safe SEH, Control Flow Guard Functions, Enclave Configuration and Volatile information in load config directory
- Edit almost every PE data structure
- Entropy, SSDEEP, TLSH, CRC32, ImpHash, MD5, SHA1, SHA256 and Authentihash calculation of the files
- View strings including URL, Registry, Suspicious, ... embedded in files
Website: https://mzrst.com/