A modern PE static analysis tool for reverse engineers, malware analysts, and security researchers.
PE Explorer+ helps you quickly inspect, understand, and analyze Portable Executable (PE) files through a modern and intuitive interface.
PE Explorer+ is designed to simplify PE analysis without sacrificing the information security researchers need.
Instead of relying on multiple utilities, PE Explorer+ brings common PE analysis workflows into a single application.
It combines essential PE inspection features with compiler identification, embedded executable detection, digital signature verification, .NET metadata inspection, UPX unpacking, and an advanced strings viewer in a clean and responsive interface.
- Rich Header Analysis -> Detect and analyze Rich Header structures with raw and decoded hex views.
- PE structure analysis (PE32 / PE32+)
- Compiler and packer identification (powered by Detect It Easy)
- Embedded PE detection and dumping
- Digital signature verification
- UPX unpacking
- Advanced Strings Viewer
- Resource Viewer
- .NET Metadata Viewer
Parse Rich Header structures and display raw and decoded hex data.
Detect embedded PE files inside executables and extract them with a single click.
Browse ASCII and Unicode strings with filtering and search capabilities.
Inspect executable resources including icons, dialogs, menus, bitmaps, and Delphi forms.
Explore .NET metadata tables, streams, and assembly information.
Examine file contents with a built-in hexadecimal viewer.
Even for non-PE files, Hex View and Strings Viewer remain available for quick inspection.
See PE Explorer+ in action.
demo.mp4
PE Explorer+ requires the Microsoft .NET 10 Desktop Runtime.
If the runtime is not installed, Windows will prompt you to install it before launching PE Explorer Plus.exe.
PE Explorer+ performs static analysis and does not intentionally execute the analyzed file.
However, untrusted files should still be handled in an isolated environment.
Download the latest version from the GitHub Releases page.
The release package contains:
- PE Explorer Plus.exe
- LICENSE.txt
- THIRD_PARTY_NOTICES.md
- CHANGELOG.md
PE Explorer+ includes or integrates the following third-party software:
- Detect It Easy (MIT License)
- UPX (GPL v2 with the UPX Special Exception)
For more information, see THIRD_PARTY_NOTICES.md.
PE Explorer+ is free to use for personal, educational, research, and internal business purposes.
See LICENSE.txt for details.
If PE Explorer+ has been useful in your work, you can support its development.








