Page 2 of 2

Re: PPEE - Professional PE file Explorer

Posted: Tue Jun 27, 2017 7:10 pm
by billon
Wow, with new YARA plugin, it can replace good old PEiD in regards of detection
YARA rules

pestudio completely sucks

Re: PPEE - Professional PE file Explorer

Posted: Tue Aug 29, 2017 1:38 am
by __philippe
And just in case someone else was still wondering about YARA wonders : :wink:

Explain YARA Rules to me, pretty please... 8)

Re: PPEE - Professional PE file Explorer

Posted: Thu Sep 21, 2017 4:36 am
by __philippe
And just as luck would have it...;-)

YARA Rules practical application (*)
(in the context of the recent CCleaner v5.33 hacking episode.)

(*) aka: Shutting the stable door after the horse has bolted... :roll:

Re: PPEE - Professional PE file Explorer

Posted: Tue Aug 21, 2018 12:11 am
by PPEE
Hi. New version(1.12) of PPEE (puppy) is out!
Download: https://www.mzrst.com/

Changes in v1.12:
  • Rich Header supported (Experimental)
  • Resolve ordinal to name in imported APIs
  • File description of imported modules is shown
  • Filter/Search box added for listview
  • PE type icon added in statusbar
  • .ini file converted to UTF
  • SHA256 and ImpHash added in FileInfo plugin
  • Bugfixes
any suggestion or bug-report is appreciated

Re: PPEE - Professional PE file Explorer

Posted: Wed Aug 22, 2018 1:35 am
by Midas
Thank you for the update and welcome to our Forum, PPEE. 8)

Re: PPEE - Professional PE file Explorer

Posted: Wed Aug 22, 2018 2:31 am
by PPEE
Midas wrote: Wed Aug 22, 2018 1:35 am Thank you for the update and welcome to our Forum, PPEE. 8)
Oh ;), Hi everybody! I'm happy to be here :D

Re: PPEE - Professional PE file Explorer

Posted: Wed Aug 22, 2018 10:57 am
by __philippe
Welcome onboard , Majid ! :D

Thanks for PPEE v1.12 nice complement of new features and also for upholding support under good ole Win XP ! 8)

Also appreciate PPEE runs flawlessly when invoked from CLI command,
which can't be said of some well known competing product (which shall remain nameless ) :wink:

Re: PPEE - Professional PE file Explorer

Posted: Wed Aug 22, 2018 11:22 am
by PPEE
__philippe wrote: Wed Aug 22, 2018 10:57 am Welcome onboard , Majid ! :D

Thanks for PPEE v1.12 nice complement of new features and also for upholding support under good ole Win XP ! 8)

Also appreciate PPEE runs flawlessly when invoked from CLI command,
which can't be said of some well known competing product (which shall remain nameless ) :wink:
That's very kind of you ;) I have also explained some of the recent features of PPEE in a blog post https://www.mzrst.com/blog/2018/08/18/p ... -features/

Re: PPEE - Professional PE file Explorer

Posted: Fri Nov 10, 2023 4:33 am
by Midas
Topic update: PPEE v1.13 released 2023-11-07 (no online changelog apart from the one included in program's archive).

Spoiler!   

FTR, here's PPEE full available changelog:

Code: Select all

>> 2023-11-07 Released Version 1.13 <<
- Now PPEE is independent of Microsoft redistributable package
- Added Recent Files in the main PPEE menu
- Load Config parsing improved to the newest version
- Undecorate mangled names
- Timestamps are human readable (relative to your local time)
- YaraPlugin is now compatible with yara v4.3.2
- Added Recent Files in the YaraPlugin
- TLSH hash added in FileInfo plugin
- Bugfixes

>> 2018-08-17 Released Version 1.12 <<
- Rich Header supported (Experimental)
- Resolve ordinal to name in imported APIs
- File description of imported modules is shown
- Filter/Search box added for listview
- PE type icon added in statusbar
- .ini file converted to UTF
- SHA256 and ImpHash added in FileInfo plugin
- Bugfixes

>> 2018-04-06 Released Version 1.11 <<
- Remeber window size and position
- Added Authentihash(PE256) in FileInfo plugin 
- Shell integration support added for dll, cpl and ocx files
- Autocheck for new version at program start up
- Bugfixes

>> 2017-10-10 Released Version 1.10 <<
- Fixed bug in parsing Manifest resource
- Fixed bug in parsing non PE files
- Improved Metadefender compatibility in FileInfo plugin 
- Fixed listview item select in Wine
- Improved edit capability

>> 2017-06-27 Released Version 1.09 <<
- Yara rules supported(New plugin)
- Application manifest item added to Treeview
- Resource type detection added
- Treeview tooltips added
- Rearrange Debug Dir. items
- Show file size in binary unit(FileInfo plugin)
- Major Bugfixes

>> 2017-03-29 Released Version 1.08 <<
- Plugin revised (Get query report through system proxy)
- Horizontal divider added
- GUI is improved
- Major bug fixes

>> 2016-09-10 Released Version 1.07 <<
- Virustotal and OPSWAT's Metadefender query report is added to the plugin
 (Without submitting the file)
- Suspicious strings treeview item added
 (Customizable via Suspicious.txt file)
- Timedate stamp now shown in UTC standard, with days passed
- Statusbar shows basic PE info
- Minor bug fixes

>> 2016-07-08 Released Version 1.06 <<
- GUI is improved
- Anomaly detection added
- Check update menu item added
- Toolbar and Statusbar Added
- Added RightClick context menu to copy or search
- Dump Sections, Resources and .Net assembly directories
- Separated items for URL, Registry, File strings
- Minor bugs in .Net directory fixed
- Fuzzy hash(ssdeep) support by plugin

>> 2016-04-22 Released Version 1.05 <<
- .Net assembly VtableFixup support
- Control Flow Guard support
- New highlighting scheme
- Treeview icon added
- Neater Listview
- Major bug fixes

>> 2015-07-19 Released Version 1.04 <<
- Descriptive information is added
 (Plus sign means, it is not a member of the structure)
- Full Resource directory support
- Companion plugin revised
- Some minor bug fixes

>> 2015-05-02 Released Version 1.03 <<
- Entropy and MD5 of the sections are added
- GUI is improved
- Companion plugin revised (File entropy and CRC32)
- Some major bug fixes

>> 2012-09-28 Released Version 1.02 <<
Now puppy can bite! It means puppy is gonna become a PE editor.

- You are allowed to edit most of the data directory structures
- Plugin enabled (For more information refer to Plugins.txt)
- A very simple built in hex editor is supplied (A little buggy)
- "Strings in file" item is added to tree view which can show
  ASCII/UNICODE strings in a PE.
- List view columns can sort data in an appropriate way
- Refresh, Save and Save as menu commands added
- Some major bug fixes

>> 2012-08-05 Released Version 1.01 <<
- Tree view accepts single click
- Main window is now resizable
- List view is colorized
- Some minor bug fixes

Re: PPEE - Professional PE file Explorer

Posted: Fri Nov 10, 2023 1:30 pm
by Special
PPEE v1.13.1 released as of today, nothing was added in the readme/changelog though...

Re: PPEE - Professional PE file Explorer

Posted: Sat Nov 11, 2023 4:59 am
by __philippe
Forensic 🔎 introspection of v1.13 and v1.13.1 binaries (C:\ppee ppee.exe:wink: ) reveal,
under the "Rich Header" 🔬 tab, at least one notable difference beween run time modules :
they were produced by different C++ compiler versions.