TeamVanilla

About NiTools

A static file analyzer by TeamVanilla, a game development and research & development company.

What it is

NiTools is the tool we open first with an unfamiliar binary: how it was built, what it imports, what it talks to, whether it is packed or signed, and where the interesting code is. It began as part of our NiSuite tools and was rebuilt for teamvanilla.dev in 2026.

How it works

The page loads the analysis code into a worker in your browser tab. The file is read into that worker and nowhere else. Parsers for PE, ELF, Mach-O, Android binary XML and ZIP read the structure; detectors look at imports, strings, entropy and structure; a verdict weighs what they found.

The weights were set against 1,570 known-good programs and libraries from Windows and Program Files: ordinary software creates processes, writes the registry and reads the clipboard, so none of that alone counts against a file.

Disassembly uses iced-x86, compiled to WebAssembly, which loads once a file with x86 or x64 code has been analysed; the code is then read once in the same worker for cross-references and the code views. Signatures are checked with the browser's own WebCrypto.

What is recorded

The file itself is never sent anywhere. When an analysis finishes, the page sends the NiTools account service:

  • the file's name, size and SHA-256;
  • a summary: the file type, the architecture, the score and its level, the titles of up to six findings, whether it is signed, the packer if one was found, and counts of imports, exports and sections;
  • your IP address, which the service sees with any request.

The address counts the free analyses for visitors without an account. Signed-in users see their records under Your history on the NiTools page and can delete any of them. Administrators can see the records to run the service.

Signing in uses Discord. NiTools asks Discord for your user name and avatar, not your email address. The session is kept in a cookie that scripts cannot read and that is sent only to teamvanilla.dev. Choosing the theme or saving your own structs stores them in your browser only.

If the account service cannot be reached, files are still analysed and nothing is recorded.

Built on

  • iced-x86 by the iced project and contributors (MIT licence) decodes x86 and x64 instructions.
  • MITRE ATT&CK names the techniques capabilities map to. ATT&CK is a trademark of The MITRE Corporation.
  • The PE, Authenticode, ELF, Mach-O, DEX and ZIP formats are read from their public specifications.

Contact

Questions, false positives and files NiTools reads wrongly: tell us on our Discord.