解剖 · kaibō — dissection, byte by byte

Leviathan Forensics

A sharp, practical workbench for binary inspection and incident-response digging — without leaving VS Code.

Open a file, choose a tool, and start pulling useful signals out of the bytes. Made for analysts, reverse engineers, CTF players and curious developers who like their evidence close at hand.

A suspicious attachment needs a first pass. Firmware needs a careful look. A binary puzzle needs structure, strings and entropy in one place — not scattered across six terminals. Leviathan gathers the whole forensic kit into a dedicated activity-bar view and a right-click toolbox on any file in the Explorer.

From the Explorer

One click

Tools in one place

Dozens

Findings, kept together

Case exports

道具 · the toolbox
十六進 · hex

Inspect the bytes

A hex editor for close reading, plus fast overviews: hashes, entropy, strings, timestamps and metadata at a glance.

捜索 · hunt

Find what matters

Hunt for IOCs and interesting patterns. Run single searches or multi-searches across the whole binary.

比較 · compare

Spot the difference

Two files look similar — Leviathan shows you exactly where they part ways, and carves data out of larger blobs.

構造 · structure

Go deeper

Structures, disassembly, keys, patches and transforms — with views for PDF, SquashFS, spectrograms and steganography checks.

Load a binary, pick the analysis view you need, and follow the clues. When you're done, export the case so the trail is kept together rather than lost in scrollback.

好機 · good moments for it

— A suspicious attachment lands and needs a first pass before anyone touches it.

— Firmware needs a careful, methodical look.

— A binary puzzle needs structure, strings and entropy side by side.

— You want forensic tools in the editor instead of scattered across terminals.

The feel

Purposeful, dense, and a little dramatic in the best way: a proper workbench for byte-level investigation.

入手 · get it

Install it and start digging.

Leviathan Forensics is on the Visual Studio Marketplace. The same toolkit also runs entirely in the browser at leviathan.dixon.cx — over twenty tools, no upload.

Install from Marketplace

A format it should handle, but doesn't?

Suggestions for new parsers, views or analyses are always welcome — tell me what you're up against.

Send me a message →