6 Hex Editors for Malware Analysis

My article on the SANS Forensics Blog describes 6 hex editors for analyzing malware and malicious documents. I outlined and compared key features for:

  • FileInsight
  • Hex Editor Neo
  • FlexHex
  • 010 Editor
  • Hiew
  • Radare

The tools differ in their ease-of-use and features. Of these, FileInsight and 010 Editor are my picks for Windows, and Radare is my favorite for Unix.

Lenny Zeltser 

Updated

About the Author

Lenny Zeltser is a seasoned business and tech leader with extensive cybersecurity experience. He builds innovative endpoint defense solutions as VP of Products at Minerva Labs. Beforehand, he was responsible for security product management at NCR Corp. Lenny also trains incident response and digital forensics professionals at SANS Institute. An engaging presenter, he speaks at industry events, writes articles and has co-authored books. Lenny has earned the prestigious GIAC Security Expert designation, has an MBA from MIT Sloan and a Computer Science degree from the University of Pennsylvania.

Learn more