Skip to content

Latest commit

 

History

767 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Binary101

Binary101 is a browser-based static web application for inspecting binary files. The app runs entirely in the browser using TypeScript/JavaScript (ES modules) and is built with Vite into a static site. There is still no server-side code.

Inspiration and Purpose

This project draws inspiration from tools like regex101, the Linux file utility, and VirusTotal. It is designed for educational and research purposes, helping users understand binary file structures and formats. By analyzing files locally in the browser, it ensures privacy and security, making it suitable for sensitive files.

Features

  • Deep analyzers: Detailed views for PE/COFF (PE32/PE32+), MS-DOS MZ, ELF 32/64, Mach-O (32/64/FAT), PNG, BMP, TGA, JPEG, GIF, WebP (RIFF), WAV (RIFF), AVI (RIFF), ANI (RIFF), ASF (WMV/WMA), WebM/Matroska, MP4/QuickTime/3GP (ISO-BMFF), MPEG Program Stream (MPEG-PS), PCAP, PCAP-NG, gzip, PDF, TAR, ISO-9660, ZIP (DOCX/XLSX/PPTX/OpenXML), 7z, RAR v4/v5, MP3, FLAC, FB2, SQLite, LNK.
  • PE limitations: CodeView/PDB extraction is currently RSDS-only; NB10 and other legacy NBxx CodeView records are not decoded yet. Missing .pdata formats include 32-bit MIPS, Windows CE ARM/PowerPC/SH3/SH4, and Itanium.
  • Instruction-set detection: for ELF and PE on x86/x86-64, the app can analyze sampled reachable code and report the instruction-set extensions it uses.
  • Detected/labelled: text/HTML/XML/SVG/JSON/RTF/shebang, TIFF, ICO/CUR, bzip2/XZ/LZ4/Zstandard, CAB, OGG/AIFF/MIDI/AMR/AC3/DTS, FLV, MPEG-TS, RealMedia, Java class, Android DEX, WebAssembly, Windows Help (HLP), PDB, DjVu, Microsoft Compound File (DOC/XLS/PPT/MSI/CHM), HEIF/HEIC, and ZIP-based labels for FB2, ODT/ODS/ODP, EPUB, DOCX/XLSX/PPTX/OpenXML, APK, VSIX, JAR/WAR/EAR/JMOD, and XPS.
  • Rendering: previews for supported audio/video/image types.
  • Hashing: SHA-256 and SHA-512 computed in-browser.
  • Privacy: No uploads or network calls for analysis.

Usage

  • Drag and drop a file onto the page, paste a file, or use the file picker.
  • View detailed analysis of the file structure and computed hashes.

Development

  • npm run dev — start the Vite dev server.
  • npm run build — create the production build in dist/.
  • npm run preview — serve the built site locally on http://127.0.0.1:4173.
  • npx tsx scripts/rustPeMatrix.ts — build a Rust PE matrix with the local rustc toolchain and run each output through the PE analyzer/renderer. Results are written to %TEMP%\binary101-rust-hello-bin\matrix\ (commands.txt, summary.md, and per-variant parse.json / rendered.html).
  • npm run build:pe-samples — build local hello-world PE samples from samples/pe-disassembly/ with the available C/C++/C#/Rust/Go/Zig/Pascal/D and assembly toolchains. Results are written to %TEMP%\binary101-pe-disassembly-samples\.
  • npm run generate:winapi-metadata — download the pinned Microsoft.Windows.SDK.Win32Metadata NuGet package, extract Windows.Win32.winmd, and generate PE import-enrichment JSON assets.
  • npm run generate:ucrt-metadata — download pinned Windows SDK C++ packages and generate UCRT PE import-enrichment JSON assets.
  • npm run validate:api-metadata — validate generated WinAPI and UCRT metadata manifests and per-DLL chunks.
  • npm run build:with-api-metadata — generate and validate PE import metadata, then build the static site.
  • PE import metadata details live in docs/pe-import-metadata.md.
  • Microsoft C++ RTTI support and its strict relocation-backed detection contract are documented in docs/msvc-rtti.md.
  • NativeAOT reflection-metadata detection and its strict relocation-backed validation contract are documented in docs/native-aot-metadata.md.

Project Structure (high level)

  • index.html & style.css — Vite HTML entry and page styling.
  • app.ts — UI wiring: file selection, hashing, dispatch to analyzers and renderers; Vite bundles it into dist/assets/.
  • analyzers/ — TypeScript binary format detection and parsers. PE/COFF logic lives under analyzers/pe/ and is split into small modules (headers, imports/exports, resources, TLS, CLR, relocations, Authenticode, exception data, etc.); CodeView debug parsing is currently RSDS-only, and some .pdata variants are still not implemented.
  • renderers/ — TypeScript HTML renderers for parsed structures. The PE renderer lives under renderers/pe/ and is split into headers, directory views, resources, and layout/sanity views.
  • binary-utils.ts, html-utils.ts — shared helpers for hashing, byte/hex formatting and safe HTML generation.

Contributing

Please see CONTRIBUTING.md

License

This project is licensed under the MIT License. See LICENSE for details.

Used by

Contributors

Languages