We use cookies.This website uses essential cookies to operate core features. With your consent, we also use analytics cookies to understand traffic and improve the service. For more details, see our .
Was this tool helpful to use?
Your feedback helps us make it better
Extract files from Windows and Linux PyInstaller programs and attempt to recover Python source from bytecode.
Choose filesDrop a file here, or click to choose
.exe · .bin · .elf
Max 5 MB
Upload limits: guest 5 MB, member 10 MB, advanced/professional 20 MB.
The executable is parsed as data and is never run. Results depend on bytecode version and opcode support; PYC files are kept when decompilation fails.
Overview
Understand what the tool solves, how it works, and the boundaries of its data.
PyInstaller bundles a Python interpreter, application modules, and supporting files into a distributable program. A one-file build commonly appends an archive to the executable. That archive may contain compressed .pyc modules, native libraries, images, configuration, and other resources. This tool attempts to read Windows/Linux .exe, .bin, and ELF inputs, list recognizable members, extract them, and then try to process Python bytecode it finds.
Decompilation does not recreate the original project. Comments, whitespace, original variable names, and other pre-compilation details are usually absent from bytecode. Reconstructed files are an approximation of the program represented by that bytecode. Modules that cannot be converted remain available as bytecode, while extracted resources can still help explain package layout and dependencies.
Guide
Follow the workflow and verify inputs and outputs with practical examples.
Choose a Windows or Linux PyInstaller program that you own or are authorized to inspect. Check its name, target platform, and provenance before submitting an unfamiliar binary.
After selecting the file, review the account upload limit shown on the page and start processing. The parser reads archive metadata and member data; it does not launch or execute the uploaded program.
Download the ZIP when processing finishes. Read its notes or report first, then inspect resources, native extensions, and recovered Python files by directory. Filenames and package paths can help map output back to application modules.
Compare entry modules and key call paths with logs, configuration, and dependency manifests. If bytecode remains, note its Python version and use a compatible analysis method before drawing conclusions.
Use cases
See how the tool fits into real work and everyday tasks.
A maintainer can export the archive listing to see whether a release included configuration, templates, certificates, or native libraries before deciding which modules need deeper recovery.
A development team can inspect bundled modules and resources while tracing missing-file errors, launch failures, or differences between Windows and Linux builds.
A security analyst can examine archive contents and bytecode clues without running the target. Suspicious files still belong in the organization’s established malware-analysis workflow.
Q&A
Find concise answers to common questions and confusing cases.
Recovery depends on the bytecode version and supported instructions. Compilation also removes comments, original formatting, and some naming details. The tool can only reconstruct what remains; unsupported modules may be kept as bytecode or listed in the report.
The parser targets PyInstaller formats used in Windows/Linux programs and normally does not need to run the target. Architecture, build options, and extra packing can still affect detection, so verify important findings with another archive viewer or the original environment.
No. It reads binary and archive structures and does not start the EXE or ELF or call its entry point. Avoid opening files from unknown sources on a regular workstation even when they came from an extraction ZIP.
Record the bytecode header and Python version, then try a decompiler that supports that version. Encryption, truncation, obfuscation, or corruption can make source recovery impossible; retain the original bytecode for later analysis.
Notes
Review scope, result limitations, and important precautions before use.
PyInstaller releases, one-file versus one-folder layouts, compression such as UPX, custom bootloaders, and additional encryption can all change what the parser recognizes. A readable archive does not guarantee that every module can be reconstructed. Keep skipped and failed items in the report with the ZIP so the result is interpreted as a whole.
Submit only files you own or are authorized to analyze. This is static data inspection, not a safety verdict, and recovered code should not be deployed without review. For commercially sensitive programs, follow your organization’s data-handling rules and inspect the extracted archive before sharing it.
Related
Discover related tools, collections, and available API capabilities.