Rehex – Reverse Engineers' Hex Editor
github.com
github.com
It's very powerful, lets you display in multiple different formats (not just 1/2/4/8 bytes, but interlaced formats and byte-arrays) and has the most amazing templating / scripting engine I've seen for this type of tool.
The only caveat is that it isn't free, but if this is something you do for a living (as I do) it's an indispensable tool for exploring file formats and other binary data sources.
010 Editor is one of the few commercial tools that I just have to have a license for - I don't use it to make a living, but I've participated in some CTFs and challenges, and just yesterday I noticed that a WAV file had metadata which I didn't know was a thing, so I just opened it in 010 Editor with the WAV template and I could see how the metadata was stored, and all other fields!
The template executes like a script (with conditionals and looping) and a line like "int32 myNum;" is actually just syntactic sugar for "read 4 bytes from the current file pointer and label it myNum." Their example probably does a better job explaining it than I can:
struct FILE {
struct HEADER {
char type[4];
int version;
ushort numRecords;
} header <bgcolor=cLtGray>;
struct RECORD {
int employeeId;
char name[40];
float salary;
if( file.header.version > 1 )
int numChildren;
if( file.header.version > 2 )
time_t birthDate;
} record[ file.header.numRecords ];
} file;
( From: https://www.sweetscape.com/010editor/templates.html )I used it a lot when datamining in World of Warcraft - I would find reverse engineered documentation from previous versions of the game, write it into a 010 editor template struct, run it on the DBC file and then I'd usually get a result where the header and the first few fields would be fine, but the rest would be completely wrong. All I did was add a field in the template before the first obviously wrong field, with different, random sizes, to add random padding until the field started looking correct again.
It's a pretty specific case, but it almost always worked!
If you are considering this, get the Pro version. I would recommend to the owner to just make the non-pro version free.
Because I'd love templating feature like that works at the bit level.
IOW: you can specify some a bunch of fields to be, say, 3 bits each, and that when all the bits of a byte are used, it simply spills over to the next byte.
(Long-time reverse-engineer. My go-to hex editor is still HIEW.)
HxD is a bit sentimental to me as it's the hex editor I used over a decade ago when figuring out that you could flip one bit at a deterministic position in Game Maker executables to enable the debugger for release builds. A small find, since soon after someone else figured out how to extract the whole source from release builds
You can use the schema in a number of programming languages then, and if you wanted to compare files it might be a few more steps but you could export your data as json and get a semantic diff vs "4 bytes changed at offset 1294".
The yaml based language is awful to use. It doesn't support bit level reading, so you can't do unaligned bit reading, used often in networks packets.
utf8-debom() {local SED=gsed; $SED -i '1s/^\xEF\xBB\xBF//' $@}
The principe seems very good, like a wireshark for binary files. Not sure how powerful it is in practice.
It can browse the hierarchy behind a binary format, down to individual fields (even bits).
API offers edition capabilities.
It has graphical (wx) and textmode (python-urwid) interfaces.
Hachoir is able to open invalid / truncated files. Here are the available commands:
hachoir-grep
hachoir-metadata
hachoir-metadata-csv
hachoir-metadata-gtk
hachoir-metadata-qt
hachoir-strip
hachoir-subfile
hachoir-urwid
hachoir-wxIn UI, a lack of consistency hurts regardless of whatever preference. Which is why all these toolkits was a mess back in the days. Which is why applications have the ability to follow whatever preference the user set in UI (light, dark, solarized, etc). Ignoring following default choice, a lack of choice for dark mode therefore always hurts dark mode users.
While dark mode during day is perfectly fine, light mode during night does not cut it for me. I usually go for dark mode full brightness in day, and half brightness during night (after sundown).
I've played a little bit with hexl-mode in Emacs; does anyone know of any extensions/built-in functions that can do some of what's going on here with Rehex?