Reverse Engineering Unknown File Formats with ImHex
werwolv.net
werwolv.net
Eventually I wrote another little BASIC program to run analytics, like which customers spent the most with us, and auto-fix mistyped names ("This says 'Bb Jones'. Did you mean 'Bob Jones'?") by writing directly to the file.
I got a pretty sweet little bonus for my hackery.
BASIC is over 40 years older than me, and I have never played with it, thus my question :-)
It went by previous records. I'd read something about Levenshtein distance somewhere, and implemented my own half-assed version of it that was surely slower, more complicated, and less accurate. It still got the job done, though. I showed it to a coworker, who described it as "magic", and I floated on that compliment for a long time after.
I was pretty proud of it, although the resulting QBasic code was pretty awful in retrospect. It was probably my first commercial-scale project, built with the software that happened to ship with the computer.
This “database” allowed me to automate nearly my entire job - finding and exercising test cases for policy bug reports with a calculator - which gave me time to experiment with software development. I’d gone to college to be a writer, but this was waaaay cooler.
I didn’t get a bonus - heck I’d have been fired for sure - but that time spent learning made my entire career possible. Hoping to get another ten years before AI eats it all.
So but words like "database" and "sql" scared the shit out of me at the time. I was doing most of my coding out of a starbucks in Eagle Rock and there was one other guy there on a laptop, John P, who kept looking at what I was writing and telling me I had to learn databases.
What I ended up coding was basically a database based on text files and pages and a custom encoding methods and a system for locking. Imagine a year later in 1999 when I realized this had all been solved and I'd been too stubborn to try it or understand what it did...
Fast forward a few years and someone put two sequential asterisks in in the name of a product and blew up the site and my encoding system, since they'd accidentally stumbled on the row break symbol. lol. Good times.
The program is so good, and has enough of a reputation that I knew to reach for it even though I know nothing about reversing, and that was 3-4 years ago now! Also shoutout to the awesome GUI library is uses; https://github.com/ocornut/imgui
Past attempts to use after downloading and running it natively have revealed it to be very crashy. Trying the browser-based demo today and doing the first thing that comes to mind (loading a ZIP) produces an error that the pattern language interpreter can't resolve the "import std.mem" line, for which there seem to be no hits on Google.
The poor font rendering is also not ideal, nor the fact that the "immediate mode" approach to the GUI (perversely favored by the kinds who tend to identify with software craftsmanship, including ostensible focus on performance, including opposition to bloat and unnecessary resource use) also means fans are constantly spinning up. Running these kinds of apps is basically the same as running a game...
It would be really nice to be able to roundtrip C headers with it. The syntax is close, but often I older formats there is a 1:1 mapping with C structs that doesn’t quite match the imhex syntax.
- it comes from a game called splinter cell conviction made in custom unreal 2.5
- I have neither been able to get UE-Explorer or UEViewer to work with it
- I can send you the file, I just want to know how to change enemy AI spawn types on it
- the post itself quotes "I usually couldn’t really give them a good answer except, “Look at the decompiled code of whatever program reads/writes these files and work backwards from there.”
- i dont have the program and that is the real challenge
I have this game, Game Name exact version, which I love and I logged hundreds of hours in it, however there's this little detail that bothers me like a pebble in a shoe: (details of the problem here). I think that it's all encoded in the file (file name), but it's binary and I have no idea how to access it :(
Could you perhaps guide me how to analyse and "decode" this file so I could later change this behaviour? I don't have any experience with reverse engineering but I'm excited to try.
All game files are in /full/path/to/the/game
Thanks!"
Works for me.
Be excited, frame it as a learning opportunity, make sure it's obvious its for your own enjoyment (not for distribution).
If the file's too big, you'll probably need to download a harness/local app. If you go local route, make sure you have a backup in case the LLM breaks the file
The local route it can also try to poke at the binaries that read/write the file so it would have a bit more to work with going that route
[1] https://www.moddb.com/games/star-wars-republic-commando/tuto...
It wouldn't at all suit a general purpose compiled programming language (the best you can do there is templates or similar), but here it seems really neat. I haven't looked into it (maybe this exists), but I would love to see this DSL as a library or a code generator, to help with parsing custom binary formats in my own programs. This is much easier for this specific purpose than even parser combinators (which is what I would typically use, e.g. winnow in Rust).
I assumed it was proprietary and left it at that.
A few years later, I saw that Onshape allows importing sldprt files into their system and I wonder how they were able to provide that ability without some proprietary knowledge transferred
I wish I read something like this article at that time!
A lot of Microsoft formats are open standards... Created by and only used by Microsoft...
does this also
Error: imhex: Cask 'imhex' has been disabled because it does not pass the macOS Gatekeeper check! It was disabled on 2026-09-01.
tbt to reverse engineering the original PokemonGo rpc
The other thing worth checking early is whether the file is compressed or checksummed. If entropy is flat and high across the whole file it is probably deflate or an encrypted blob, and hex staring will get you nowhere until you unwrap it. And if there is a 4 byte value near the header or footer that changes on every save even when the data is identical, treat it as a CRC or timestamp before assuming it is data. Writing back an edited file that fails the checksum is the classic reason a patched save silently refuses to load.
I may feed it into an LLM to strip out the spoilers actually