Inspect native PE import declarations
Read direct and delay imports from local x86 PE32 or x64 PE32+ files, keep name/ordinal and source hashes, and export complete JSON plus formula-safe CSV in one ZIP.
- 1Add input
- 2Review and run
- 3Get your result
Tool input and files are processed in this browser without being uploaded.
Before you start
Inspect import declarations without loading a DLL or executing an EXE. Selected-file matches compare only finite names and machine declarations; use the complete ZIP when deciding what to investigate next.
How to use this tool
- Select the local native PE files whose import declarations you need; original bytes remain unchanged.
- Run the inventory and inspect direct/delay modules, symbol counts and finite selected-file statuses.
- Download pe-imports.zip; read every JSON declaration and CSV symbol row with its source SHA.
- Use suitable authorized Windows tooling for actual loader, API-set, export or trust questions.
Supported inputs and limits
1–100 local files, at most20MiB each and80MiB together;1–96 sections per file,10,000 import descriptors and100,000 imported symbols across the set. Every budget applies together.
Only native x86 PE32 and x64 PE32+ with uniquely file-backed RVA tables. CLR, other machines and bound-only imports without an original lookup table are unsupported. Delay imports allow PE32 RVA/legacy VA and PE32+ RVA only; PE32+ legacy VA is unsupported.
Imported module/symbol names are printable ASCII ASCIIZ, at most4,096 bytes. Selected basenames must be printable ASCII without path separators. Named RVA thunks use31 bits; ordinal reserved bits, header/section boundaries, table terminators and directory declarations are checked.
Matching uses only ASCII case folding among selected basenames. not-selected means no same-name file was selected; selected-declaration means a unique selected name/machine declaration matches. Ambiguous names and machine mismatches are explicit. These states do not establish exports, trust, DLL availability or Windows loading.
API-set names are virtual OS contracts, without a guaranteed same-name disk DLL. No OS search, API-set host mapping, recursive dependency resolution, file fetch, DLL loading, code execution or signature/trust audit occurs.
pe-imports.zip contains exactly pe-imports.json and pe-imports.csv. Complete report bytes together allow32MiB; the fixed two-member STORE headers add232 bytes. The34MiB ZIP guard is dominated by that report budget, not another reachable report-size axis. Reused long names are charged before report expansion.
JSON retains every source SHA/byte count, section, descriptor, raw thunk, name/hint/ordinal and selected-file status. CSV has every imported-symbol row; descriptors without symbols and files with no imports remain explicit in JSON. CSV formula prefixes are neutralized without changing raw JSON names.
The interface previews the first200 module declarations, long cells first2,000 UTF-16 units. Copy gives full JSON up to20,000 UTF-16 units and an explicit summary above it; complete JSON/CSV always remain in ZIP. Malformed, unsupported, over-limit or cancelled work publishes no partial ZIP.
Worked example
Example input
One1024-byte synthetic x86 PE32 named root.exe.
Example options
No editable parameters.
Example output
2 module declarations,4 imported symbols; finite not-selected statuses and complete JSON/CSV ZIP.
When something does not work
Check the actual machine/header profile, ASCII basenames and declarations, all bounds and total budgets. Choose supported originals or a smaller complete set. Errors or cancellation leave no partial ZIP; correct the input and rerun the same selected bytes.
Frequently asked questions
Does not-selected mean a DLL is missing?
It only says no same-name basename was selected in this bounded input set. Windows loader search and API-set host mapping are outside this static inventory.
Does a selected-declaration match prove the program will run?
It compares one selected name and machine declaration. Exports, versions, signatures, policy, recursive dependencies and actual loading are not evaluated.
Why are some delay imports unsupported?
The finite profile accepts PE32 legacy VA and RVA delay descriptors, and PE32+ RVA descriptors. PE32+ legacy VA and reserved or malformed address declarations refuse the entire operation.
Documentation & further reading
Related tools
JSON formatting workspace
Format or minify strict JSON, sort object keys, and encode or decode strings while preserving raw number tokens.
Regex tester
Try a pattern and see what it matches in your text.
Compare text
See what changed, side by side.
HTML formatter
Format HTML indentation so its structure is easier to read.