
Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump in-memory PE files and reconstruct imports.
PE Tree is a Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. It can also be used with IDA Pro, Ghidra, Volatility, Rekall and minidump to view and dump in-memory PE files, as well as perform import table reconstruction.
The PE Tree standalone application finds portable executables in files, folders and ZIP archives.

Install directly from GitHub using a fresh virtual environment and pip:
> virtualenv env
> env\Scripts\activate
> pip install --upgrade pip
> pip install git+https://github.com/blackberry/pe_tree.git
$ python3 -m venv env
$ source ./env/bin/activate
$ pip install --upgrade pip
$ pip install git+https://github.com/blackberry/pe_tree.git
Git clone the repository and setup for development:
> git clone https://github.com/blackberry/pe_tree.git
> cd pe_tree
> virtualenv env
> env\Scripts\activate
> pip install -e .
$ git clone https://github.com/blackberry/pe_tree.git
$ cd pe_tree
$ python3 -m venv env
$ source ./env/bin/activate
$ pip install -e .
Run PE Tree and scan for portable executables in files, folders and ZIP archives:
$ pe-tree -h
usage: pe-tree [-h] [filenames [filenames ...]]
PE-Tree
positional arguments:
filenames Path(s) to file/folder/zip
optional arguments:
-h, --help show this help message and exit
Run PE Tree and attempt to carve portable executable files from a binary file:
$ pe-tree-carve -h
usage: pe-tree-carve [-h] filename
PE-Tree (Carve)
positional arguments:
filename Path to file to carve
optional arguments:
-h, --help show this help message and exit
Dark-mode can be enabled by installing QDarkStyle:
$ pip install qdarkstyle
The PE Tree IDAPython plugin finds portable executables in IDA databases.

To install and run as an IDAPython plugin you can either use setuptools or install manually.
Download pe_tree and install for the global Python interpreter used by IDA:
$ git clone https://github.com/blackberry/pe_tree.git
$ cd pe_tree
$ python setup.py develop --ida
Copy pe_tree_ida.py to your IDA plugins folder
Download pe_tree and install requirements for the global Python interpreter used by IDA:
$ git clone https://github.com/blackberry/pe_tree.git
$ cd pe_tree
$ pip install -r requirements.txt
Copy pe_tree_ida.py and the contents of ./pe_tree/ to your IDA plugins folder
To forgo installing as a plugin, and simply run as a script under IDA, first install the pe_tree package requirements for the global Python installation: