About Site Map Submit Contact Us Log in | Create an account
Create an account Log In
Average Rating
User Rating:
Visitors Rating:
My rating:

Write review
  • License: Freeware
  • Last update: 6 years ago
  • Total downloads: 114
  • Price: Free |
  • Operating system: WinXP, Win2003, Win2000, Win Vista, Windows 7
  • Publisher: Daniel Pistelli
See full specifications

windows default iconPE Detective Publisher's description

Created by Daniel Pistelli, a freeware PE identifier.

Created by Daniel Pistelli, a freeware PE identifier. This tool was originally designed to be part of the Explorer Suite II, but it can be downloaded separately as well. The PE Detective can scan single PE files or entire directories (also recursevely) and generate complete reports. The PE Detective is deployed along with the Signature Explorer, which is an advanced signature manager to check collisions, handle, update and retrieve signatures.

To scan a file is very easy with the PE Detective tool: just drag & drop a file on the interface and press scan. If there are multiple results, all of them will be listed in descending priority. The data for each result shows the signature name, the number of matches (meaning how many bytes in the signature match, wildcards aren't counted) and possible comments regarding the signature.

It's, also, possible to perform a directory scan through the PE Detective. This means that every file in that directory will be scanned and listed in the results. The scan can be performed recursevely. As you can see, through the pop-up menu you can generate a complete report of the scanning session.

The PE Detective comes along with the Signature Explorer, an advanced signature manager. This manager can open a signature database (there's one for each supported platform and a platform independent dabatase) and add, modify and delete its signatures. Entire PE Signatures are only used when the Deep Scan option is enabled. Those kind of signatures are scanned through the entire PE.

To retrieve new signatures to add to the database, there's a Signature Retriever utility. This utility retrieves common bytes (at a certain RVA and given a maximum signature lenght) of two or more applications. The default RVA is the application entrypoint.

Update is an easy task. Through the update utility you can update the current loaded signature database online or from file. There's an option to show only not-already-existing signatures and you can still delete all the items you don't want to add to the database.

The last utility provided by the Signature Explorer is a Collision Checker. Basically, it checks the current loaded database for collisions (meaning already existing signatures). The check can be done specifying various options. When the scan is completed, already existing signatures are showed in collision groups and each signature has a different colour depending on how it collides with the other signature in its collision group. You can also delete from the same interface all the signatures which you think of being redundant. Warning: for huge database files the scan might take a while and it's only there to preserve the database's integrity.


* File Scanner
* Directory Scanner
* Deep Scan method
* Recursive Scan method
* Multiple results
* Report generation
* Signatures Manager
* Signatures Updater
* Signatures Collisions Checker
* Signatures Retriever

System Requirements:

No special requirements.
Program Release Status:
Program Install Support: Install and Uninstall

PE Detective Tags:

Click on a tag to find related softwares

Is PE Detective your software?

Manage your software

Most Popular

DownloadPlex.com Software Updater icon DownloadPlex.com Software Updater
DownloadPlex.com Software Updater is freeware allow you can check new software version in your system
AVG-PC Tuneup 2012 2012.26.c1 icon AVG-PC Tuneup 2012 2012.26.c1
Restore your PC to peak performance Speeds up your PC, cleans your hard driveand eliminates freezing
DAEMON Tools 4.40.0311 icon DAEMON Tools 4.40.0311
DAEMON Tools Pro is CD %26 DVD emulation software which allows users to make CDDVD disc images, create a... Read more
Hamster Free Zip Archiver icon Hamster Free Zip Archiver
Hamster Free Zip Archiver is a new, absolutely free, file archiver which allows you to quickly and easily work... Read more
windows default icon CMP Wassup 2.5 Build 9436
This Applet will show you all the Java system properties

Related Category

» Backup & Restore (1596)
» Benchmarking (42)
» Clipboard Tools (162)
» Other (3958)
» Printer (209)
» Registry Tools (287)
» Shell Tools (187)