NiTools logoNiTools logo

NiTools

Static analysis of any file, in your browser.

NiTools reads any file and lays out what's inside it. It runs at teamvanilla.dev/nitools/: drop a file on the page and a worker in your browser tab parses it. The file is never uploaded, and there's nothing to install.

It's the tool we reach for first with an unfamiliar binary: how it was built, what it imports, what it talks to, whether it's packed or signed, and where the interesting code is.

What it reads

FilesWhat you get
Windows programs and librariesEvery header field with its offset, sections, imports and exports, resources with icons and version information, the Authenticode signature checked against the file, the Rich header, debug data, TLS callbacks, relocations and unwind data. x86 and x64 disassembly with control flow and call graphs, cross-references and stack frames; C++ classes from RTTI with their fields.
Linux and Android native codeELF sections, program headers, symbols, needed libraries and hardening. x86 and x64 disassembly.
macOS and iOSMach-O load commands, libraries, segments and hardening. x86-64 disassembly.
Android packagesThe manifest, permissions, components other apps can start, signing schemes, DEX files and native libraries.
ZIP archivesEvery entry, each one saveable.
Anything elseHashes, strings, indicators, embedded files and keys, crypto constants, entropy, a Hilbert map, byte pairs and a hex viewer.

The views

NiTools has 58 views in seven groups. A file gets the ones that have something to show for it.

SummaryThe score and its findings, the main facts about the file and its hashes.
StructureHeaders, sections, imports and exports, resources, strings, indicators, components, embedded files, the signature, the overlay, debug data, the Rich header, relocations and timestamps.
CodeDisassembly, the control flow graph, functions, the call graph, cross-references, thunks, stack frames, TLS callbacks and unwind data.
ReconstructionC++ classes, their hierarchy and field layouts, strings the code builds on the stack, imports looked up by name at run time, and a demangler for Microsoft and GCC/Clang names.
SecurityCapabilities and their MITRE ATT&CK techniques, anti-analysis, signs of packing, system calls, crypto, network use, rule matches, a YARA rule for the file, anomalies and mitigations.
VisualisationEntropy across the file, a Hilbert map and byte pairs.
ToolsHex, search, struct templates, XOR, comparing two files, matching the functions of two builds, notes and bookmarks, and exports: reports, IDA and Ghidra scripts and an x64dbg database.

The score

Every file gets a score from 0 to 100 for how much of what NiTools can see points at packed, evasive or hostile code, with each finding explained. The weights were set against 1,570 known-good programs and libraries from Windows and Program Files: NiTools scores 1,549 of them low, 21 in the middle band and none high. A score isn't a verdict. Static analysis can't tell what a program will do, only what it contains.

Its import hash is the one pefile and VirusTotal compute, its C++ demangler prints Microsoft's names the way Microsoft's own undname does, and it checks an Authenticode signature by hashing the file itself.

Accounts and what is recorded

Without an account you get three free analyses; the NiTools page shows how many are left. Signing in with Discord raises the total to five, and Premium accounts have no limit. NiTools asks Discord for your user name and avatar, not your email address.

The file never leaves your browser. When an analysis finishes, the page records the file's name, size and SHA-256, a short summary and your IP address, which is how the free analyses are counted and how signed-in users get a history they can delete from. About NiTools lists exactly what is sent.