$npx skillfedfor your agent

dissect.cstruct

A Dissect module implementing a parser for C-like structures: structure parsing in Python made easy

Worth itPyPI UtilitiesReleased Nov 2025227.9K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — dissect_cstruct-4.7-py3-none-any.whl
v4.7 · released 2025-11-20 · Python >=3.10

Yes. Zero dependencies, active maintenance, stable API, and Apache-2.0 licensing make it a low-risk choice. Install if you need to parse binary data with C-like structures; the straightforward syntax and ability to reuse real C definitions from open-source projects make it significantly more practical than manual struct.unpack() calls for complex formats.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • Low install friction with no runtime dependencies.
  • Active maintenance since 2018, last commit 2026-08-10, and marked Production/Stable.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions.

last release 2025-11-20 (267 days) · last repo commit 2026-08-10 · 66 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 227,946 downloads/mo, #9,162 on PyPI

Verify before relying

from dissect.cstruct import cstruct

parser = cstruct().load("""
struct example {
    uint8 a;
    char b[5];
};
""")

data = b"\x01hello"
result = parser.example(data)
print(result.a, result.b)
  • Whether compiled structures (the default) provide measurable performance gains for typical workloads.
  • Compatibility with structure definitions from specific C projects or standards beyond the Linux kernel example given.
Same gist for agents: .md · .json

What it is and what it does

dissect.cstruct is a binary structure parser that lets you define C-like structures in a simple text format and use them to parse raw binary data into Python objects. It handles common C constructs—basic types, arrays, enums, unions, nested structures, and bit fields—with minimal syntax overhead. You write a structure definition, load it into a parser instance, then call the resulting structure class on binary data (bytes or file-like objects) to get back a Python object with typed fields that you can read, modify, and serialize back to bytes.

The library is designed for simplicity: no complex syntax, filters, or preprocessing—just straightforward structure parsing. It's particularly useful for reverse-engineering binary file formats, parsing kernel data structures, or handling custom binary protocols where you can reuse structure definitions from existing C codebases with little or no modification. It compiles structures to optimized Python classes by default for better performance.

Use it for

  • Parse EXT4 superblocks or other kernel data structures by copying C definitions from Linux source.
  • Reverse-engineer custom binary file formats by defining their layout and parsing samples.
  • Handle binary network protocols or file formats where you need bidirectional serialization.
  • Parse forensic or log data with fixed binary layouts in incident response workflows.
  • Work with embedded device data or firmware images with known C struct definitions.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Zero dependencies, active maintenance, stable API, and Apache-2.0 licensing make it a low-risk choice. Install if you need to parse binary data with C-like structures; the straightforward syntax and ability to reuse real C definitions from open-source projects make it significantly more practical than manual struct.unpack() calls for complex formats.

Install

dissect-cstruct on PyPI

Before you install

Low install friction with no runtime dependencies. Active maintenance since 2018, last commit 2026-08-10, and marked Production/Stable.

Requires Python 3.10 or later.

License in practice

Apache-2.0 permissive license allows commercial and private use with minimal restrictions.

Quickstart

from dissect.cstruct import cstruct

parser = cstruct().load("""
struct example {
    uint8 a;
    char b[5];
};
""")

data = b"\x01hello"
result = parser.example(data)
print(result.a, result.b)

Verify before relying

  • Whether compiled structures (the default) provide measurable performance gains for typical workloads.
  • Compatibility with structure definitions from specific C projects or standards beyond the Linux kernel example given.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 267 days since the last release
Last repo commit
First released
Downloads227,946 / month, #9,162 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: Information TechnologyOperating System :: OS IndependentProgramming Language :: Python :: 3Topic :: Internet :: Log AnalysisTopic :: Scientific/Engineering :: Information AnalysisTopic :: SecurityTopic :: Utilities

Evidence: dissect_cstruct-4.7-py3-none-any.whl

Tags

Capabilities
binary data parsingC struct parserbinary format parsingstruct unpackingbinary serializationC-like structuresbyte parsing
Topics
binary-parsingforensicsreverse-engineering

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “binary data parsing”

  • dissect.cstructParse binary data using C-like structure definitions, converting raw…
  • constructConstruct is a declarative parser and builder for binary data that…
  • pycstructConverts binary data to and from Python dictionaries or objects using…

Give your agent the search over MCP, or paste the wish link into any chat.

More Utilities packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
charset-normalizer Worth it
PyPI · Utilities · released Aug 2026

Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.

permissive licensepure Python · 3.7+
1.7Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
pluggy Worth it
PyPI · Libraries · released May 2025

Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.

Install it if you're building an extensible application or framework.

MITpure Python · 3.9+aging
1.3Bdownloads / mo
Pygments Worth it
PyPI · Utilities · released Mar 2026

Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.

Install it if you need to display or transform source code.

BSD-2-Clausepure Python · 3.9+
1.3Bdownloads / mo
six With conditions
PyPI · Libraries · released Dec 2024

Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.

MITpure Python
1.2Bdownloads / mo

See also dissect.ntfs · pycstruct · bitstruct · dissect.hypervisor · dissect.volume · dissect.target · construct-classes · RoffIO · cbitstruct · pymp4