Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
pecli — 用于分析PE文件的CLI工具 | Kitploit
工具/GitHubGitHub/te-k/pecli
静态分析逆向工程恶意软件分析二进制分析
GitHubte-k/pecli

pecli

用于分析PE文件的CLI工具

查看仓库
9023142年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

PEcli

用于分析 PE 文件的 Python 3 工具。当前功能:

  • 显示文件信息(导入、导出、资源)
  • 搜索文件中的有趣信息(异常资源、peid...)
  • 转储节或资源
  • 检查大小
  • 在文件中搜索字符串

PyPI PyPI - Downloads PyPI - License GitHub issues

安装

你可以从 pypi 安装它:pip install pecli

或者直接从源代码安装:

git clone https://github.com/Te-k/pecli.git
cd pecli
pip install .

使用方法

PEcli 通过插件工作,例如 pecli PLUGIN FILE

usage: pecli [-h] {check,checksize,crypto,dump,info,richpe,search,shell,sig,strings,vt} ...

positional arguments:
  {check,checksize,crypto,dump,info,richpe,search,shell,sig,strings,vt}
                        Plugins
    check               检查文件中的内容
    checksize           检查 PE 文件的大小
    crypto              识别加密值
    dump                转储文件的资源或节
    info                从 PE 文件中提取信息
    richpe              解码 Rich PE 头
    search              在 PE 文件中搜索字符串
    shell               启动 ipython shell 分析 PE 文件
    sig                 处理 PE 签名
    strings             从 PE 文件中提取字符串
    vt                  在 VirusTotal 中检查 PE 信息

示例:

$ pecli info explorer.exe
Metadata
================================================================================
MD5:           418045a93cd87a352098ab7dabe1b53e
SHA1:          98b9ad668e0727be888b861f49aac0f72725e634
SHA256:        81419093ccb985da284931fa3df41c4cfe25350db1c366792903411819371664
Imphash:       c3eb9567e9430e65e703dca7bb8343fa
Size:          1036800 bytes
Type:          PE32 executable (GUI) Intel 80386, for MS Windows
Compile Time:  2008-04-13 19:17:04 (UTC - 0x48025C30)
Entry point:   0x101a55f (section .text)
Debug Information: explorer.pdb

Sections
================================================================================
Name       VirtSize  VirtAddr  RawSize   RawAddr   Entropy  md5
.text      0x44c09   0x1000    0x400     0x44e00   6.3838   8c58c76b600f5aee7f7c7242454b9a1f
.data      0x1db4    0x46000   0x45200   0x1800    1.2992   983f35021232560eaaa99fcbc1b7d359
.rsrc      0xb2f64   0x48000   0x46a00   0xb3000   6.6381   f7df812e2e64b1514d61a9681fbe71da
.reloc     0x374c    0xfb000   0xf9a00   0x3800    6.7817   ec335057489badbf6d8142b57175fd91


Imports
================================================================================
ADVAPI32.dll
	0x1001000 RegSetValueW
	0x1001004 RegEnumKeyExW
	0x1001008 GetUserNameW
[SNIP]

Resources:
================================================================================
Id           Name    Size      Lang           Sublang           Type           MD5
2-143-1031   None    2040 B    LANG_GERMAN    SUBLANG_GERMAN    data           f0e8e299c637633db0a5af11042adb04
2-145-1031   None    35322 B   LANG_GERMAN    SUBLANG_GERMAN    data           1e5bfaf34503ce750b3cc13058a3f88b
2-146-1031   None    12826 B   LANG_GERMAN    SUBLANG_GERMAN    data           061daf6ef2047f33947d5655f1c8aaa4
[SNIP]
$ pecli check playlib.exe
Running checks on playlib.exe:
[+] Abnormal section names: .enigma1 .enigma2
[+] Suspicious section's entropy: .enigma1 - 7.931
[+] Known malicious sections
	-.enigma1: Enigma Virtual Box protector
	-.enigma2: Enigma Virtual Box protector
[+] 200 extra bytes in the file
[+] TLS Callback: 0x446bb0
[+] PE header in sections .enigma2
[+] Known suspicious import hash: Enigma VirtualBox

许可证

本工具采用 MIT 许可证发布

类似工具

  • Viper
  • PEScanner 由 Michael Ligh 为 Malware Analyst's Cookbook 发布(仅限 python2)
  • Manalyze 由 Ivan Kwiatkowski 编写
  • 在 Windows 上:PeStudio、PEView 和 Resource Hacker
下载工具