pestudio

pestudio comes in both a basic and a professional version, with the professional edition providing unique features unavailable in the basic release. This software is offered 'as-is', without any explicit or implicit guarantees. Under no circumstances shall the author be responsible for any damages resulting from the use of pestudio.

basic
free

Malware Analysis in a private context.

  • Detect file signature
  • Detect hard-coded URLs and IP addresses
  • Collect metadata
  • Collect imports, exports, strings
  • Retrieve manifest, resources, overlay
  • Retrieve score from virustotal
  • ...
professional
159 Euro/user /year

Malware Analysis in a professional context.

  • All features of the basic version
  • Use pestudio in batch mode with pestudiox.exe
  • Show items by groups and colors
  • Create XML report file
  • Show MITRE | ATT&CK mapping
  • Show .NET namespaces
  • Dump .NET embedded file(s), etc...