CLI Overview¶
ppee-cli is PPEE's headless frontend. It prints any part of a PE file as human-readable text or JSON, patches fields, feeds the similarity database, and runs as an MCP server.
Synopsis¶
Options come first and the file comes last. Exactly one input file is accepted per run; to process many files, see batch recipes.
How the options fit together¶
flowchart TD
A[ppee-cli args] --> B{--help / --version / --mcp?}
B -- yes --> Z[print / serve and exit]
B -- no --> C[Load file]
C --> D{--set given?}
D -- yes --> E[Apply edits in order]
E --> F{--save?}
F -- yes, all edits OK --> G[Write file or -o PATH]
D -- no --> H
F -- no --> H
G --> H[Analyze selected sections]
H --> I{--json?}
I -- yes --> J[JSON document on stdout]
I -- no --> K[Text report on stdout] The options fall into four groups:
| Group | Options | Reference |
|---|---|---|
| Section filters: choose what to include | --headers --dirs --sections --hashes --similarity --imports --exports --basereloc --tls --debug --bound-imports --delay-imports --resources --exception --security --loadconfig --net --richheader --appmanifest --analysis --analysis-deep --strings --all | Section filters |
| Output: choose how it is printed | --json --timing | Output options |
| Editing: change the file | --set --save -o | Editing options · --set address syntax |
| Behavior and modes | --no-similarity --no-update-check --mcp --mcp-allow-write --help --version | Behavior options |
No filter means everything
If you give no section filter, PPEE behaves as if you passed --all. Once you give one filter, only the sections you name are printed.
stdout, stderr and exit codes¶
- stdout carries only the report (text or JSON), so
ppee-cli --json … | jqalways receives valid JSON. - stderr carries diagnostics: edit and save confirmations, warnings,
--timingoutput and update notices.
| Exit code | Meaning |
|---|---|
0 | Success |
1 | Bad usage (unknown option, missing file, more than one file), the file could not be read, the file is not a valid PE, any --set edit failed, or the save failed |
Environment variables¶
| Variable | Effect |
|---|---|
PPEE_JOBS=<n> | Number of worker threads. The default is the number of CPUs the process may use, which respects container CPU quotas and affinity masks (see Docker CPU limits) |
Platform differences¶
| Behavior | Windows | Linux | Docker |
|---|---|---|---|
| Startup update check | Yes (disable with --no-update-check) | No | No (the image passes --no-update-check) |
Signature validity (WinVerifyTrust) in --security | Yes | "Not available on this platform" | Same as Linux |
| Path encoding | Arguments in the ANSI code page; MCP paths as UTF-8 | UTF-8 | UTF-8 |
| Similarity DB location | Next to ppee-cli.exe | Next to ppee-cli | /ppee/ppee-cli.similarity.db |
Next¶
- All options with examples
- Editing with
--set - JSON output schema
- Recipes: batch processing, jq one-liners, triage scripts