{"adoption": {"forks": 173, "observed_at": "2026-08-28T04:04:26.436305+00:00", "stars": 1343}, "canonical_url": "https://ross.abutalabs.com/products/pe_tree", "card": {"archived": true, "artifact_type": "application", "description": "Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump in-memory PE files and reconstruct imports.", "domain": ["security", "reverse-engineering", "windows", "developer-tools"], "enriched": true, "function": ["reverse-engineering", "gui", "parser", "security"], "health_score": 10, "homepage": null, "language": "Python", "license": "Apache-2.0", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["blackberry/pe_tree"], "name": "blackberry/pe_tree", "platform": ["python", "windows", "cross-platform"], "pushed_at": "2022-07-09T03:36:38+00:00", "repo": "blackberry/pe_tree", "stars": 1343, "tags": ["pe-files", "malware-analysis", "ida-pro-plugin", "ghidra-plugin", "volatility", "memory-forensics", "import-reconstruction", "binary-carving", "pyqt5", "pefile", "linux", "macos", "desktop"], "topics": [], "urls": [], "use_cases": ["inspect PE headers of an exe or dll in a tree view", "dump in-memory PE files from a Windows memory dump", "reconstruct import tables of an unpacked malware sample", "carve PE files from a binary blob", "analyze a Windows minidump for embedded executables", "view PE files inside IDA Pro or Ghidra", "compare PE samples visually with a rainbow PE map"], "what_it_is": "PE Tree is a Python module and standalone GUI application for viewing Portable Executable (PE) files in a tree-view, built on pefile and PyQt5. It integrates with IDA Pro, Ghidra, Volatility, Rekall, and minidump to dump in-memory PE files and reconstruct import tables.", "when_to_avoid": ["you only need programmatic PE parsing without a GUI (use pefile directly)", "you analyze non-PE formats like ELF or Mach-O", "you need automated bulk analysis rather than interactive inspection"], "when_to_choose": ["you need a visual tree-view of PE file structures", "you are doing malware analysis or memory forensics on Windows binaries", "you want to dump and reconstruct PE files from memory dumps or minidumps", "you want a plugin for IDA Pro, Ghidra, Volatility, or Rekall"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/pe_tree", "repo": "blackberry/pe_tree", "role": "main", "score": 10}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:26.436305+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:42:53.402899+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7e573bd6f87e72ae996ab528906454c8ec99b5076f021ab49885c149b845134f", "fetched_at": "2026-08-28T04:04:26.436305+00:00", "kind": "readme", "missing": false, "url": "https://github.com/blackberry/pe_tree"}, {"content_hash": "dae05478883ddc41590d40771616d5cfac4ba4b4e05d3bb8ee3c7a10a1917694", "fetched_at": "2026-08-29T12:02:13.407641+00:00", "kind": "registry_pypi", "missing": false, "url": "https://pypi.org/pypi/pe_tree/json"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["archived"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2228, "days_push": 1516, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 10, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}