6 Hex Editors for Malware Analysis

My article on the SANS Forensics Blog describes 6 hex editors for analyzing malware and malicious documents. I outlined and compared key features for:

  • FileInsight
  • Hex Editor Neo
  • FlexHex
  • 010 Editor
  • Hiew
  • Radare

The tools differ in their ease-of-use and features. Of these, FileInsight and 010 Editor are my picks for Windows, and Radare is my favorite for Unix.

Lenny Zeltser 

Updated

About the Author

Lenny Zeltser develops products and programs that use security to achieve business results. He is the CISO at Axonius and Faculty Fellow at SANS Institute. Lenny has been leading efforts to establish resilient security practices and solve hard security problems for over two decades. A respected author and practitioner, he has been advancing tradecraft and contributing to the community. His insights build upon real-world experience, a Computer Science degree from the University of Pennsylvania, and an MBA degree from MIT Sloan.

Learn more