NiTools
Static analysis of any file, in your browser. Open a program, a library, an Android package or anything else and see what is inside it. The file is read in this tab and never uploaded.
Drop a file anywhere on this page
or
Up to 1 GB. Several files open side by side in tabs. Pasting a file works too.
What it reads
Any file. These get a full breakdown; everything else gets the tools in the last row.
-
Windows programs and libraries
.exe.dll.sys.efi.scr- Structure
- Every header field with its offset, sections, imports and exports, resources with their icons and version information, the Rich header, debug data, TLS callbacks, relocations and unwind data.
- Signature
- The Authenticode signature, checked against the file itself.
- Code
- x86 and x64 disassembly with control flow and call graphs, cross-references, stack frames, stack strings and the imports it looks up at run time.
- Classes
- C++ classes from RTTI, their hierarchy and their fields.
- Security
- Signs of packing, system calls, capabilities mapped to MITRE ATT&CK, and a YARA rule for the file.
- Export
- Reports, and the names and notes as an IDA script, a Ghidra script or an x64dbg database.
-
Linux and Android native code
ELF.soexecutablesSections, program headers, symbols, needed libraries and hardening, with x86 and x64 disassembly.
-
macOS and iOS
Mach-OuniversalLoad commands, libraries, segments and hardening, with x86-64 disassembly.
-
Android packages
.apkThe manifest, permissions, components other apps can start, signing schemes, DEX files and native libraries.
-
ZIP archives
.zip.jar.docx.xapkEvery entry, each one saveable.
-
Anything else
any fileHashes, strings, indicators, embedded files and keys, crypto constants, entropy, a Hilbert map, byte pairs and a hex viewer.
Every file also gets a score from 0 to 100 for how much points at packed, evasive or hostile code, with each finding explained. The guide goes through all 58 views.
What leaves your browser
None of the file.
It is read and analysed by a worker in this tab; for x86 and x64 code the disassembler loads into the same tab once the analysis is done.
When an analysis finishes, NiTools records the file's name, size and SHA-256, a short summary (the type, the score, the titles of the top findings, a few counts) and your IP address. That is how the free analyses are counted, and how signed-in users get a history they can delete from. Exactly what is sent.
Accounts
Optional.
Without an account you get a few free analyses; the line under the drop area says how many are left.
Signing in with Discord raises the total to five free analyses; Premium accounts have no limit. NiTools asks Discord for your user name and avatar only, never your email address.
Your history
The files you analysed while signed in: their name, size, SHA-256 and summary, never their contents. Delete any of them.