The whole workbench
for unknown bytes.

Leviathan is a complete binary analysis, reverse-engineering and digital-forensics workbench — hex editor, signature scanner, disassembler, structure parser, certificate inspector, PDF surgeon and steganography toolkit — gathered into one quiet interface.

Built-in analysis runs inside the page. The moment you drop a file, analysis begins without uploading the artefact. No analysis telemetry. Your bytes stay local unless full-trust plugin code sends them elsewhere.

Drop a file. See everything.

Analysis readyLocal
111recognised formats
29 panels0 bytes uploaded
The principles

Private by default

Built-in analysis never uploads your artefact. Raw bytes stay local unless full-trust plugin code you choose to load sends them elsewhere.

Truthful over flashy

Every panel is marked solid, partial or heuristic. When a tool is guessing, it tells you so.

Everything in one place

Bookmarks, evidence, hashes, patches and diffs are shared across every panel and bundled into one case file.

Built for large files

Open multi-hundred-megabyte firmware images and the hex editor stays smooth. Only what is on screen is drawn.

111Embedded-file formats
29Analysis panels
6Disassembled ISAs
0Artefact bytes uploaded
The tools

One side dock. Every panel shares the same hex view, the same bookmarks and the same evidence log. Click any result anywhere to jump the editor to that offset.

Hex editor

Solid

Virtualised, chunk-backed rows that scroll through hundreds of megabytes. Type two hex digits to patch a byte; every edit is reversible. A live minimap charts entropy, search hits, bookmarks and diffs.

Inspector

Solid

The byte under the cursor, read as every common type at once — integers 8–64 bit LE/BE, floats, ASCII / UTF-8 / UTF-16, and the usual timestamp formats. Is it a size, a pointer, or an epoch? See all the answers together.

Search

Solid

ASCII, hex with ?? wildcards, or full regex — streamed over the whole file in chunks, carrying matches across boundaries. Every hit is clickable and pinned on the minimap.

Embedded Files

Solid

Everything hiding inside the file you opened, in one list. 111 signatures name what an object is — archives, compression, filesystems, executables, firmware, media, crypto — and 25 structural validators establish exactly where it ends, so what you extract actually opens. Bounded deep scan keeps nested payloads and labels their containment depth.

Structures

Partial

Auto-detects PNG, JPEG, GIF, BMP, ZIP, ELF, PE, Mach-O and RIFF, with manual ASN.1 / DER and certificate parsing. PE exposes imports, exports and resources; ELF exposes program headers, sections, symbols and dynamic entries.

Templates · DSL

Solid

A compact language for arbitrary binary layouts: structs, enums, consts, conditionals, arrays sized by prior fields and a full expression grammar. Write a template, apply it, and every field cross-links into the hex view.

Entropy & Hashes

Solid

Shannon entropy over a configurable window makes encrypted blobs pop out of readable firmware. Streaming CRC32, MD5, SHA-1/256/512 over the whole file or any selected range.

Fuzzy hash & PE triage

Solid

ssdeep-compatible similarity scoring for related samples, plus PE imphash and 14 CAPA-like import capability groups for rapid behavioural triage.

Strings & IOCs

Solid

Printable ASCII and UTF-16 string extraction, then a regex-driven indicator extractor with 15 categories — IPs, domains, URLs, hashes, CVEs, registry keys, paths and more.

Certificates & Keys

Solid

Scans for PEM and DER X.509 certificates — subject, issuer, validity, algorithms, SANs, fingerprint — and sweeps for embedded private keys: PKCS#1/#8, EC, OpenSSH, PKCS#12 markers.

PDF surgery

Solid

Enumerates every object, walks the full filter chain and object streams, decodes xref tables and streams, and surfaces suspicious constructs — JavaScript, embedded files, OpenAction, launch and URI actions.

Steganography

Solid

Trailer detection across image, audio and RIFF formats; LSB extract / inject over PNG IDAT, BMP pixels and WAV samples; and a deep metadata walk — PNG text chunks, JPEG segments and a full EXIF dictionary.

Disassembly

Solid x86 · heuristic others

Full integer x86/x86-64 decoding plus honest heuristic ARM, Thumb, AArch64 and MIPS. Builds CFGs, xrefs and bounded call graphs; ELF symbols, PE exports and image entries seed a clickable function inventory with complexity metrics.

Preview

Partial

Renders embedded media in place — PNG/JPEG/GIF/BMP/WebP, WAV/MP3/OGG/FLAC, MP4/MKV — straight from an Embedded Files hit or a highlighted range, without extracting it first.

Transforms & Cipher

Experimental

Chain hex, base64, XOR and inflate into a pipeline that shows each stage. The cipher bench brute-forces Caesar, Atbash, XOR and Vigenère with an English-frequency score for trivially-obscured text.

SquashFS & Compare

Partial

A read-only SquashFS 4.x extractor that walks the directory tree and pulls individual files (gzip / xz / zstd). Load two files and Compare diffs them by chunk, highlighting every change.

FAT filesystems

Solid

Read-only FAT12/16/32 browsing with VFAT long names, guarded cluster-chain walking, per-file extraction and best-effort recovery of deleted directory entries.

EWF disk images

Solid

Open a single EnCase/EWF1 (.E01) acquisition the same way as any other file — Leviathan reconstructs the raw disk image transparently, so the hex view, FAT filesystems and every other panel work on it directly. EWF2 (.Ex01) and multi-segment .E01+.E02+… acquisitions are not read.

Evidence & case integrity

Solid

Records an append-only evidence log, seals entries into a SHA-256 chain, optionally signs the root with Ed25519, and carries the chain into a portable case ZIP.

…and Rules (YARA-like), Timestamps, Bookmarks, Patch scripting, the Bookmarks, patch scripting, the Command palette and a full-trust Plugin API. Each panel publishes its own honesty status.

Unknown firmware image → explained, in under five minutes.

No command line, no scattered tools, no temporary files on disk. One tab, one file.

# drop firmware.bin onto the page — analysis begins immediately
embedded   deep scan → uimage @ 0x0   ·   gzip @ 0x40   ·   squashfs @ 0x200000
squashfs   open → walk tree → extract /etc/shadow
keys       scan → 2 RSA private keys found in the kernel region
evidence   note: "two keys, likely OTA update channel"
export     case.zip  ·  manifest · hashes · bookmarks · evidence chain · patches

The case ZIP is a portable Leviathan hand-off: original and working bytes, hashes, bookmarks, patches, notes and a tamper-evident evidence chain whose root is committed in the manifest.

How it flows
  1. Drop a file onto the page — or hold Shift while dropping to load it into the Compare slot.
  2. Scan and read. Embedded Files, entropy and the inspector give you the shape of the thing in seconds.
  3. Dig in. Extract nested files, parse structures, map ELF/PE functions, decode a PDF or pull a key.
  4. Mark and note. Bookmarks and evidence entries follow you across every panel.
  5. Export the case. One ZIP holds the original, your edits, every hash, every note and every patch.

Who it's for

Malware analysts Forensic examiners Firmware RE CTF players Incident responders Pen testers Teachers & students

If it opens in a hex editor, it opens in Leviathan — and then goes much further.

Works air-gapped Once authenticated and loaded, built-in analysis needs no network access. Open and inspect local files without uploading their bytes.
For departments and larger teams

Behind the single-analyst workbench above, in the sidebar's Enterprise section: case management, role-based access, a tamper-evident audit trail, deterministic court-ready reports, and server-side execution of a curated set of native forensic tools for evidence too large for the in-browser engine. Opt-in, per case, never the default.

Case management & legal hold

Case status, legal hold, retention policy and analyst assignment, with an append-only manifest history per case.

Roles & audit trail

Analyst, reviewer, case supervisor and org admin, backed by a hash-chained, tamper-evident record of every case and admin action.

Native tool execution

ExifTool, The Sleuth Kit, YARA, binwalk, ClamAV and more, run server-side as supervised, killable jobs — only when you opt a case into it.

Fits your existing stack

Outbound webhooks into your SOC or ticketing system, and STIX export from the IOC scanner for your threat-intel platform.

Honestly: this is a working feature you can click on today, gated by role — an org-admin sees the full admin surface, an analyst sees only what their role permits, and every action is re-checked server-side regardless of what the interface shows. Get in touch if your organisation wants to evaluate it before rolling it out department-wide.

問 · Questions

Does anything leave my browser?

Raw artefacts are not uploaded for analysis, and built-in analysis runs in a dedicated worker. The hosted app uses sign-in, and trusted plugins have page-level network access, so review plugin code before loading it.

How big a file can I open?

Leviathan is built for hundreds of megabytes. The editor only renders what's on screen and the engine streams through files in chunks.

Can I extend it?

Yes. Plugins are full-trust ES modules loaded at runtime. They can register panels and use the same bridge as built-in code; only load code you have reviewed.

Where does my work go when I leave?

It persists in the browser — last-opened file, bookmarks, notes, evidence and saved templates. Come back a week later and the bench is as you left it.

From unknown blob to
explained artefact.

Sign in and the workbench opens with your last file, your bookmarks and your evidence exactly where you left them.