Inventory local native PE imports without loading them
Select a supported local PE file set, inspect ordinary and delay import declarations, and hand off complete source-proven JSON/CSV without a Windows loader claim.
Confirm the file set and inspection endpoint
Dmitry asked for native DLL dependencies without loading the DLL into a process. This tool covers the static declaration subset from selected local bytes; the original question supplied no DLL, so it does not reproduce his binary or establish actual loader behavior.
Select1–100 native x86 PE32 or x64 PE32+ files,20MiB each and80MiB together. Basenames and imported names use printable ASCII; source extensions and MIME labels do not prove support. The parser requires1–96 bounded sections and unique file-backed RVA ranges. CLR and other machines are unsupported.
Inspect declarations before reading a selected-file status
The example root.exe is a1024-byte artificial x86 PE32. It has ordinary HELPER.DLL and delay OPTIONAL.DLL declarations, each with one named and one ordinal symbol. With only root.exe selected, both modules are not-selected; this is a completed inventory rather than a missing-DLL finding.
If you also select a supported helper.dll of the same declared machine, the first module becomes selected-declaration through ASCII case folding. Two same-name selected files are ambiguous-selected; a unique other supported machine is selected-machine-mismatch. None of these outcomes checks exports or runs a loader.
| Status | Established fact | Next decision |
|---|---|---|
| not-selected | No same-name basename in this selected set | Select an intended local companion if you need finite matching |
| selected-declaration | One name and machine declaration match | Check exports, runtime environment and policy separately |
| selected-machine-mismatch | One selected name has another supported machine | Review architecture assumptions |
| ambiguous-selected | Multiple selected basenames fold to that name | Disambiguate the selected set without guessing a winner |
Read every artifact with its source provenance
pe-imports.zip has exactly two STORE members. pe-imports.json retains every source byte count/SHA, section declaration, direct/delay descriptor, raw thunk, name/hint/ordinal and matching state. pe-imports.csv contains every imported-symbol row; no-symbol modules and no-import files remain explicit in JSON.
The JSON symbol name =Danger() remains exact. CSV writes an apostrophe before that formula prefix and quotes every cell; the safe CSV cell therefore differs deliberately from the raw JSON name. Member names are controlled; input strings are inert data, not HTML or executable code.
The interface shows the first200 module rows and first2,000 UTF-16 units in long cells. Copy is complete JSON at most20,000 UTF-16 units, otherwise an explicit summary. Download the ZIP to hand off all declarations and all symbol rows; a screenshot or copied summary is not the complete report.
Check address profile and budgets together
Delay descriptors support RVA in PE32/PE32+, and legacy VA only in PE32. PE32+ legacy VA is unsupported. Ordinal reserved bits and31-bit named RVAs are strict, and undeclared import/delay directories yield complete empty lists instead of reading invented directories. Other PE directories, code, overlays, signatures and export targets are not audited; the full original SHA covers bytes without proving their meaning.
Across the set there are at most10,000 descriptors and100,000 symbols, with ASCIIZ names at most4,096 bytes. JSON+CSV together allow32MiB; fixed two-member headers add232 bytes, so the34MiB ZIP guard is dominated. Repeated long names count repeatedly in their complete JSON/CSV appearances, even if source strings share an RVA. A safe known-byte lower bound refuses expansion early; the final report is still fully measured.
Finish or recover without a loader claim
API-set import names are virtual contracts resolved through the operating system schema, which can vary by environment. A same-name disk file need not exist, and selecting a file with that spelling is only the same finite name/machine comparison. The tool does not map hosts, scan system folders, recurse, fetch or load code.
- Retain originals and use the full source SHA to identify the selected bytes.
- Choose supported input or a smaller complete set after a malformed, unsupported or budget refusal.
- Errors and cancellation publish no partial ZIP; correct the input and rerun the same selected bytes.
- Use appropriate authorized Windows tools for actual export, search, API-set, trust and loading questions.
References
- Native DLL inventory demand: Dmitry, Stack Overflow
First-person need to obtain dependencies without loading the DLL; original question checked2026-10-08, CC BY-SA3.0. No original DLL attached, reproduction or web-tool preference established.
- Microsoft PE/COFF format
Header, section, import/delay tables and reserved bits; format reference supports correctness, not demand.
- Microsoft API-set loader operation
Virtual contracts and runtime host mapping differ from basename matching; this tool does not perform that mapping.
- Microsoft DLL search order
Loader context and search policy remain outside static file declarations.
Tools in this category
Expand a tool to see its steps, options and supported formats, then open its workspace.
Inspect native PE import declarationsRead direct and delay imports from local x86 PE32 or x64 PE32+ files, keep name/ordinal and source hashes, and export complete JSON plus formula-safe CSV in one ZIP.
Inspect import declarations without loading a DLL or executing an EXE. Selected-file matches compare only finite names and machine declarations; use the complete ZIP when deciding what to investigate next.
Steps
- Select the local native PE files whose import declarations you need; original bytes remain unchanged.
- Run the inventory and inspect direct/delay modules, symbol counts and finite selected-file statuses.
- Download pe-imports.zip; read every JSON declaration and CSV symbol row with its source SHA.
- Use suitable authorized Windows tooling for actual loader, API-set, export or trust questions.
Capabilities and limits
- 1–100 local files, at most20MiB each and80MiB together;1–96 sections per file,10,000 import descriptors and100,000 imported symbols across the set. Every budget applies together.
- Only native x86 PE32 and x64 PE32+ with uniquely file-backed RVA tables. CLR, other machines and bound-only imports without an original lookup table are unsupported. Delay imports allow PE32 RVA/legacy VA and PE32+ RVA only; PE32+ legacy VA is unsupported.
- Imported module/symbol names are printable ASCII ASCIIZ, at most4,096 bytes. Selected basenames must be printable ASCII without path separators. Named RVA thunks use31 bits; ordinal reserved bits, header/section boundaries, table terminators and directory declarations are checked.
- Matching uses only ASCII case folding among selected basenames. not-selected means no same-name file was selected; selected-declaration means a unique selected name/machine declaration matches. Ambiguous names and machine mismatches are explicit. These states do not establish exports, trust, DLL availability or Windows loading.
- API-set names are virtual OS contracts, without a guaranteed same-name disk DLL. No OS search, API-set host mapping, recursive dependency resolution, file fetch, DLL loading, code execution or signature/trust audit occurs.
- pe-imports.zip contains exactly pe-imports.json and pe-imports.csv. Complete report bytes together allow32MiB; the fixed two-member STORE headers add232 bytes. The34MiB ZIP guard is dominated by that report budget, not another reachable report-size axis. Reused long names are charged before report expansion.
- JSON retains every source SHA/byte count, section, descriptor, raw thunk, name/hint/ordinal and selected-file status. CSV has every imported-symbol row; descriptors without symbols and files with no imports remain explicit in JSON. CSV formula prefixes are neutralized without changing raw JSON names.
- The interface previews the first200 module declarations, long cells first2,000 UTF-16 units. Copy gives full JSON up to20,000 UTF-16 units and an explicit summary above it; complete JSON/CSV always remain in ZIP. Malformed, unsupported, over-limit or cancelled work publishes no partial ZIP.