Skip to main content

PyPackerDetect Tweet

Detect packers on PE files using heuristics and signatures.

PyPi Python Versions Build Status DOI License

A complete refactoring of this project to a Python package with a console script to detect whether an executable is packed.

pefile is used for PE parsing. peid is used as implementation of PEiD.

$ pip install pypackerdetect
$ pypackerdetect --help
[...]
usage examples:
- pypackerdetect program.exe
- pypackerdetect program.exe -b
- pypackerdetect program.exe --low-imports --unknown-sections
- pypackerdetect program.exe --imports-threshold 5 --bad-sections-threshold 5

Detection Mechanisms

  • PEID signatures
  • Known packer section names
  • Entrypoint in non-standard section
  • Threshhold of non-standard sections reached
  • Low number of imports
  • Overlapping entrypoint sections

Related Projects

You may also like these:

Release files for pypackerdetect 1.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pypackerdetect 1.2.0
File Size Uploaded
pypackerdetect-1.2.0.tar.gz 341.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pypackerdetect 1.2.0
File Interpreter ABI Platform
pypackerdetect-1.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 653.5 kB

Release files / pypackerdetect-1.2.0.tar.gz

Download URL pypackerdetect-1.2.0.tar.gz
Size 341.4 kB
Tags Source
SHA-256 checksum
How to use checksums
a1047a0c7a924d3be2a2dbd1143ec93cae2e6201206bf4c602939708e7be7756
BLAKE2b-256 checksum
How to use checksums
6505c2717340518430da822aae0d4e706df093f454a8db85b465096b074fc31b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.

Transparency log

Release files / pypackerdetect-1.2.0-py3-none-any.whl

Download URL pypackerdetect-1.2.0-py3-none-any.whl
Size 312.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
744649b3dc20beb0b03f9dfa76c2b00f54e564cfc686b88f99a7dba2a532f893
BLAKE2b-256 checksum
How to use checksums
00aa79ebcdc92024f841b761c64d3042ebaa2e750eb8a6e3a1c25dbfcdab15af
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 19, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.2.0 This release

2 release files

1.1.4

2 release files

1.1.3

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

1 release file

1.0.5

1 release file

1.0.4

1 release file

1.0.3

1 release file

1.0.2

1 release file

1.0.1

1 release file

1.0.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page