Getting Started¶
PPEE ships as two executables built from the same core, so both show exactly the same data:
| Binary | What it is | Use it for |
|---|---|---|
ppee / ppee.exe | The desktop GUI | Interactive analysis, hex editing, browsing resources |
ppee-cli / ppee-cli.exe | The headless CLI, JSON exporter and MCP server | Scripts, Docker, CI/CD, AI assistants |
Every node in the GUI tree has a matching CLI switch. What you see in the GUI is what ppee-cli --json exports.
- Install PPEE on Windows or Linux, or pull it into Docker.
- Quick Start: analyze a file in the GUI and the CLI in five minutes.
flowchart LR
F[PE file<br/>EXE / DLL / SYS / .NET] --> Core[(ppee core parser)]
Core --> GUI[ppee GUI]
Core --> CLI[ppee-cli text / JSON]
CLI --> D[Docker image]
CLI --> CI[CI/CD pipelines]
CLI --> MCP[MCP server<br/>--mcp]
MCP --> AI[Claude & other<br/>MCP clients]