NiTools

Static analysis of any file, in your browser. Open a program, a library, an Android package or anything else and see what is inside it. The file is read in this tab and never uploaded.

Drop a file anywhere on this page

or

Up to 1 GB. Several files open side by side in tabs. Pasting a file works too.

What it reads

Any file. These get a full breakdown; everything else gets the tools in the last row.

  • Windows programs and libraries

    .exe.dll.sys.efi.scr
    Structure
    Every header field with its offset, sections, imports and exports, resources with their icons and version information, the Rich header, debug data, TLS callbacks, relocations and unwind data.
    Signature
    The Authenticode signature, checked against the file itself.
    Code
    x86 and x64 disassembly with control flow and call graphs, cross-references, stack frames, stack strings and the imports it looks up at run time.
    Classes
    C++ classes from RTTI, their hierarchy and their fields.
    Security
    Signs of packing, system calls, capabilities mapped to MITRE ATT&CK, and a YARA rule for the file.
    Export
    Reports, and the names and notes as an IDA script, a Ghidra script or an x64dbg database.
  • Linux and Android native code

    ELF.soexecutables

    Sections, program headers, symbols, needed libraries and hardening, with x86 and x64 disassembly.

  • macOS and iOS

    Mach-Ouniversal

    Load commands, libraries, segments and hardening, with x86-64 disassembly.

  • Android packages

    .apk

    The manifest, permissions, components other apps can start, signing schemes, DEX files and native libraries.

  • ZIP archives

    .zip.jar.docx.xapk

    Every entry, each one saveable.

  • Anything else

    any file

    Hashes, strings, indicators, embedded files and keys, crypto constants, entropy, a Hilbert map, byte pairs and a hex viewer.

Every file also gets a score from 0 to 100 for how much points at packed, evasive or hostile code, with each finding explained. The guide goes through all 58 views.

What leaves your browser

None of the file.

It is read and analysed by a worker in this tab; for x86 and x64 code the disassembler loads into the same tab once the analysis is done.

When an analysis finishes, NiTools records the file's name, size and SHA-256, a short summary (the type, the score, the titles of the top findings, a few counts) and your IP address. That is how the free analyses are counted, and how signed-in users get a history they can delete from. Exactly what is sent.

Accounts

Optional.

Without an account you get a few free analyses; the line under the drop area says how many are left.

Signing in with Discord raises the total to five free analyses; Premium accounts have no limit. NiTools asks Discord for your user name and avatar only, never your email address.