FAQ¶
What does PPEE stand for, and how is it pronounced?
A professional PE file explorer and editor. You may call it puppy.
Which files can PPEE open?
Any PE / PE32+ image: .exe, .dll, .sys, .ocx, .cpl, .scr, .efi, .mui, and .NET assemblies, for x86, x64, ARM and ARM64. The extension doesn't matter; PPEE checks the file's contents.
Does PPEE run the file?
No. PPEE only reads and parses files, so it is safe to use on malware samples. For extra isolation, run the CLI or the MCP server in Docker with --network none.
Do the GUI and CLI show the same information?
Yes, they share one parsing core. Every GUI tree node has a CLI switch, and every editable GUI cell has a --set address. The exceptions are visual features (hex view, navigator strip) and browsing the .NET metadata table rows, which are GUI-only (they can still be edited with --set).
Can I verify signatures on Linux?
PPEE parses signatures everywhere: signer, certificates, timestamp, and embedded digest vs Authentihash (which detects tampering). Chain trust and revocation (WinVerifyTrust) require the Windows build.
Does editing update the checksum or keep the signature valid?
No. PPEE writes exactly the bytes you change. Any change breaks an Authenticode signature, and CheckSum isn't recomputed unless you ask (--set OptionalHeader.CheckSum=auto). Use -o or Save As… to keep the original.
Why does the JSON use hex strings for numbers?
To match the GUI and the PE specification, and to keep 64-bit values exact in every JSON parser. See the jq helpers for converting them.
Does the MCP server send my files anywhere?
The server itself makes no network calls. It returns analysis results to your MCP client, and the client sends them to its model as part of the conversation, as with any MCP tool. Mount only what you're willing to share. See the security model.
Does PPEE include third-party code, and where are the licences?
Yes: Dear ImGui, GLFW and stb (GUI), TLSH, SQLite, an MD5 implementation by Alexander Peslyak, mingw-w64 (Windows builds), and the Go and Rust projects whose metadata formats the analyzers follow. Their licence notices are in THIRD-PARTY-NOTICES.txt, shipped next to every binary and inside the Docker image.
Which binaries get a runtime analysis?
Those whose runtime PPEE recognizes: .NET, Go, Rust, NativeAOT and PyInstaller. Every x86/x64 file also gets a Code analysis. See Runtime Analysis.