Private by default
Built-in analysis never uploads your artefact. Raw bytes stay local unless full-trust plugin code you choose to load sends them elsewhere.
Leviathan is a complete binary analysis, reverse-engineering and digital-forensics workbench — hex editor, signature scanner, disassembler, structure parser, certificate inspector, PDF surgeon and steganography toolkit — gathered into one quiet interface.
Built-in analysis runs inside the page. The moment you drop a file, analysis begins without uploading the artefact. No analysis telemetry. Your bytes stay local unless full-trust plugin code sends them elsewhere.
Drop a file. See everything.
Built-in analysis never uploads your artefact. Raw bytes stay local unless full-trust plugin code you choose to load sends them elsewhere.
Every panel is marked solid, partial or heuristic. When a tool is guessing, it tells you so.
Bookmarks, evidence, hashes, patches and diffs are shared across every panel and bundled into one case file.
Open multi-hundred-megabyte firmware images and the hex editor stays smooth. Only what is on screen is drawn.
One side dock. Every panel shares the same hex view, the same bookmarks and the same evidence log. Click any result anywhere to jump the editor to that offset.
Virtualised, chunk-backed rows that scroll through hundreds of megabytes. Type two hex digits to patch a byte; every edit is reversible. A live minimap charts entropy, search hits, bookmarks and diffs.
The byte under the cursor, read as every common type at once — integers 8–64 bit LE/BE, floats, ASCII / UTF-8 / UTF-16, and the usual timestamp formats. Is it a size, a pointer, or an epoch? See all the answers together.
ASCII, hex with ?? wildcards, or full regex — streamed over the whole file in chunks, carrying matches across boundaries. Every hit is clickable and pinned on the minimap.
Everything hiding inside the file you opened, in one list. 111 signatures name what an object is — archives, compression, filesystems, executables, firmware, media, crypto — and 25 structural validators establish exactly where it ends, so what you extract actually opens. Bounded deep scan keeps nested payloads and labels their containment depth.
Auto-detects PNG, JPEG, GIF, BMP, ZIP, ELF, PE, Mach-O and RIFF, with manual ASN.1 / DER and certificate parsing. PE exposes imports, exports and resources; ELF exposes program headers, sections, symbols and dynamic entries.
A compact language for arbitrary binary layouts: structs, enums, consts, conditionals, arrays sized by prior fields and a full expression grammar. Write a template, apply it, and every field cross-links into the hex view.
Shannon entropy over a configurable window makes encrypted blobs pop out of readable firmware. Streaming CRC32, MD5, SHA-1/256/512 over the whole file or any selected range.
ssdeep-compatible similarity scoring for related samples, plus PE imphash and 14 CAPA-like import capability groups for rapid behavioural triage.
Printable ASCII and UTF-16 string extraction, then a regex-driven indicator extractor with 15 categories — IPs, domains, URLs, hashes, CVEs, registry keys, paths and more.
Scans for PEM and DER X.509 certificates — subject, issuer, validity, algorithms, SANs, fingerprint — and sweeps for embedded private keys: PKCS#1/#8, EC, OpenSSH, PKCS#12 markers.
Enumerates every object, walks the full filter chain and object streams, decodes xref tables and streams, and surfaces suspicious constructs — JavaScript, embedded files, OpenAction, launch and URI actions.
Trailer detection across image, audio and RIFF formats; LSB extract / inject over PNG IDAT, BMP pixels and WAV samples; and a deep metadata walk — PNG text chunks, JPEG segments and a full EXIF dictionary.
Full integer x86/x86-64 decoding plus honest heuristic ARM, Thumb, AArch64 and MIPS. Builds CFGs, xrefs and bounded call graphs; ELF symbols, PE exports and image entries seed a clickable function inventory with complexity metrics.
Renders embedded media in place — PNG/JPEG/GIF/BMP/WebP, WAV/MP3/OGG/FLAC, MP4/MKV — straight from an Embedded Files hit or a highlighted range, without extracting it first.
Chain hex, base64, XOR and inflate into a pipeline that shows each stage. The cipher bench brute-forces Caesar, Atbash, XOR and Vigenère with an English-frequency score for trivially-obscured text.
A read-only SquashFS 4.x extractor that walks the directory tree and pulls individual files (gzip / xz / zstd). Load two files and Compare diffs them by chunk, highlighting every change.
Read-only FAT12/16/32 browsing with VFAT long names, guarded cluster-chain walking, per-file extraction and best-effort recovery of deleted directory entries.
Open a single EnCase/EWF1 (.E01) acquisition the same way as any other file — Leviathan reconstructs the raw disk image transparently, so the hex view, FAT filesystems and every other panel work on it directly. EWF2 (.Ex01) and multi-segment .E01+.E02+… acquisitions are not read.
Records an append-only evidence log, seals entries into a SHA-256 chain, optionally signs the root with Ed25519, and carries the chain into a portable case ZIP.
…and Rules (YARA-like), Timestamps, Bookmarks, Patch scripting, the Bookmarks, patch scripting, the Command palette and a full-trust Plugin API. Each panel publishes its own honesty status.
No command line, no scattered tools, no temporary files on disk. One tab, one file.
# drop firmware.bin onto the page — analysis begins immediately embedded deep scan → uimage @ 0x0 · gzip @ 0x40 · squashfs @ 0x200000 squashfs open → walk tree → extract /etc/shadow keys scan → 2 RSA private keys found in the kernel region evidence note: "two keys, likely OTA update channel" export case.zip · manifest · hashes · bookmarks · evidence chain · patches
The case ZIP is a portable Leviathan hand-off: original and working bytes, hashes, bookmarks, patches, notes and a tamper-evident evidence chain whose root is committed in the manifest.
If it opens in a hex editor, it opens in Leviathan — and then goes much further.
Behind the single-analyst workbench above, in the sidebar's Enterprise section: case management, role-based access, a tamper-evident audit trail, deterministic court-ready reports, and server-side execution of a curated set of native forensic tools for evidence too large for the in-browser engine. Opt-in, per case, never the default.
Case status, legal hold, retention policy and analyst assignment, with an append-only manifest history per case.
Analyst, reviewer, case supervisor and org admin, backed by a hash-chained, tamper-evident record of every case and admin action.
ExifTool, The Sleuth Kit, YARA, binwalk, ClamAV and more, run server-side as supervised, killable jobs — only when you opt a case into it.
Outbound webhooks into your SOC or ticketing system, and STIX export from the IOC scanner for your threat-intel platform.
Honestly: this is a working feature you can click on today, gated by role — an org-admin sees the full admin surface, an analyst sees only what their role permits, and every action is re-checked server-side regardless of what the interface shows. Get in touch if your organisation wants to evaluate it before rolling it out department-wide.
Raw artefacts are not uploaded for analysis, and built-in analysis runs in a dedicated worker. The hosted app uses sign-in, and trusted plugins have page-level network access, so review plugin code before loading it.
Leviathan is built for hundreds of megabytes. The editor only renders what's on screen and the engine streams through files in chunks.
Yes. Plugins are full-trust ES modules loaded at runtime. They can register panels and use the same bridge as built-in code; only load code you have reviewed.
It persists in the browser — last-opened file, bookmarks, notes, evidence and saved templates. Come back a week later and the bench is as you left it.
Sign in and the workbench opens with your last file, your bookmarks and your evidence exactly where you left them.