DevLune Inspector Download
DevLune Inspector

DevLune
Inspector

Read-only static analysis for Windows PE and Android. Disassembly, hidden-endpoint recovery, ATT&CK, and a built-in course. It never runs what it reads.

Windows 10/11 · 64-bit · signed auto-updates · free

Capabilities

Windows PE

Headers, sections and entropy, imports and exports, linear-sweep disassembly with cross-references, Authenticode integrity, ATT&CK.

Android

Manifest, resources, DEX and reconstructed source, native libraries and JNI, certificates, permissions and attack surface.

Recovery

Obfuscated strings (XOR, position-dependent XOR, base64) solved and surfaced as evidence, hidden endpoints included, with byte offsets.

Learn

An interactive reverse-engineering course, 50 lessons across foundations, PE and Android, run against real evidence with a Practice Lab.

Under the hood

Evidence, with a byte offset

Disassembly with cross-references

Linear-sweep x86/x64 with callers, callees, and import and string references. Walk the control flow and jump straight to the bytes.

Hidden-endpoint recovery

Strings a binary tried to hide are derived back with the exact transform and parameters, so a URL buried in a native library shows up as evidence you can re-derive by hand.

MITRE ATT&CK mapping

Imported APIs and embedded strings map to techniques the binary could perform, each with the concrete evidence that triggered it. Evidence, not attribution.

Signatures and certificates

Offline Authenticode integrity for PE and v1 to v3 signing schemes for Android, with signer identity. It reports what it verified, never more.

Learn, and a Practice Lab

A full course on how binaries and packages work, the toolbox, and how protections work in principle, with a benign specimen you load in a click.

Decision-point mapping

Where a program appears to make auth or licence decisions is mapped with its evidence. It reports the location, it never alters or bypasses the check.

Editions

Pick a build

All-in-one · recommended
DevLune Inspector
Windows PE + Android. Start here. Both engines in one tool.
Download
Windows only
PE Inspector
Windows PE. You only work with .exe, .dll, .sys.
Download
Android only
APK Inspector
Android. You only work with .apk, .aab, .so.
Download

Learn

Learn reverse engineering, on real evidence

A built-in interactive course, 50 lessons from the foundations to the deep end of PE and Android, read inside the app. A Practice Lab loads a benign specimen so every step runs against something real. It teaches how protections work in principle, for defence, and never ships a way to defeat them.

  • Foundations, then PE and Android tracks
  • Tools, formats, and how auth and licensing work
  • A Practice Lab with a real specimen
  • Read-only walkthroughs, legal practice targets

Read-only by design

Input bytes are never modified or executed. It refuses circumvention: no keygen, no auth bypass, no patching out licence or auth checks, no cracking encryption, no forging a signer, no running the analysed binary. Only analyse software you are authorised to inspect.

FAQ

Questions

Is it free?

Yes. All three editions are free, with no licence key and no account.

Does it run or install the file it analyses?

No. Files are opened as data and read on your machine. Nothing is ever executed, modified, or installed.

Which platforms does it run on?

The installers are for Windows 10 and 11, 64-bit. The analysis engines are read-only and offline.

Which edition should I pick?

The all-in-one DevLune Inspector, unless you only work one platform, in which case the slim PE Inspector or APK Inspector are for you.

Is it safe and legal to use?

It is read-only by design and refuses circumvention. Only analyse software you own or are authorised to inspect.

Does it update itself?

Yes. Every build is cryptographically signed and the app checks for signed updates on launch.

Get DevLune Inspector

Free, signed, and updating itself. Pick a build.

or open the full download pages on devlune.in