> For the complete documentation index, see [llms.txt](https://notes.incendium.rocks/pentesting-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.incendium.rocks/pentesting-notes/reversing/windows-executables-and-dlls.md).

# Windows executables and DLL's

## dnSpy

dnSpy is a debugger and .NET assembly editor. You can use it to edit and debug assemblies even if you don't have any source code available.

{% embed url="<https://github.com/dnSpy/dnSpy>" %}

<figure><img src="/files/O5yhEEQbfkstxP4uhAKX" alt=""><figcaption></figcaption></figure>

## Python compiled executable

If a executable was compiled with pyinstaller, we can extract the python compiled code and actually decompile it.

To extract use:

{% embed url="<https://github.com/extremecoders-re/pyinstxtractor>" %}

```
python pyinstxtractor.py <filename>
```

And to decompile use Uncompyle6

* Tip: use a python venv

{% embed url="<https://github.com/rocky/python-uncompyle6/>" %}

```
uncompyle6 *compiled-python-file-pyc-or-pyo*
```
