dnfile
Parse .NET executable files.
Decision gist · record as of 2026-08-14
Yes. dnfile is actively maintained, has no known vulnerabilities, installs with minimal friction, and fills a clear niche for .NET binary analysis. It is well-suited for reverse engineering, malware analysis, and metadata extraction workflows. Install it if you work with compiled .NET binaries and need programmatic access to their CLR structures.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction installation with a single runtime dependency (pefile).
- Active maintenance with recent releases; last commit 2026-08-14 and version 0.18.0 released 2026-01-31.
- Supports Python 3.8 through 3.11.
License · maintenance · safety
MIT License (permissive) — MIT license (permissive) means you can use, modify, and distribute this package with minimal restrictions, provided you include the license notice.
last release 2026-01-31 (195 days) · last repo commit 2026-08-14 · 93 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 289,581 downloads/mo, #7,999 on PyPI
Alternatives
Verify before relying
pip install dnfile
import dnfile
pe = dnfile.dnPE('path/to/binary.exe')
pe.print_info()
# Access metadata tables
for s in pe.net.metadata.streams_list:
if isinstance(s, dnfile.stream.MetaDataTables):
num_tables = len(s.tables_list)- Whether the package handles all .NET Framework versions and modern .NET Core/5+ formats equally well
- Performance characteristics when parsing very large binaries or deeply nested resource hierarchies
What it is and what it does
dnfile is a .NET executable parser that reads PE files containing Common Language Runtime (CLR) metadata and exposes their internal structure as Python objects. It wraps the lower-level PE parsing (via pefile) and adds .NET-specific interpretation: CLR directory entries, metadata streams, heap structures (strings, GUIDs, blobs, user strings), metadata tables, and .NET resources. The library is designed to tolerate partially malformed files and continue parsing what it can.
You use it when you need to inspect, analyze, or extract information from compiled .NET binaries—for reverse engineering, malware analysis, binary instrumentation, or metadata extraction workflows. Everything is exposed as an object hierarchy with raw structure values accessible via a `.struct` attribute, and the library includes shortcuts for common access patterns (e.g., `pe.net.mdtables` for the metadata tables stream, `pe.net.resources` for .NET resources).
Use it for
- Reverse-engineer or audit compiled .NET applications to inspect metadata, resources, and CLR structures
- Extract .NET assembly resources (strings, images, serialized objects) from binaries for analysis or recovery
- Analyze malware or suspicious .NET executables to identify embedded payloads or obfuscation patterns
- Build binary instrumentation or rewriting tools that need to parse and understand .NET metadata tables
- Validate or extract version, signing, and resource metadata from .NET builds in automated pipelines
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
dnfile is actively maintained, has no known vulnerabilities, installs with minimal friction, and fills a clear niche for .NET binary analysis. It is well-suited for reverse engineering, malware analysis, and metadata extraction workflows. Install it if you work with compiled .NET binaries and need programmatic access to their CLR structures.
Install
dnfile on PyPI
Before you install
Low friction installation with a single runtime dependency (pefile). Active maintenance with recent releases; last commit 2026-08-14 and version 0.18.0 released 2026-01-31. Supports Python 3.8 through 3.11.
License in practice
MIT license (permissive) means you can use, modify, and distribute this package with minimal restrictions, provided you include the license notice.
Quickstart
pip install dnfile
import dnfile
pe = dnfile.dnPE('path/to/binary.exe')
pe.print_info()
# Access metadata tables
for s in pe.net.metadata.streams_list:
if isinstance(s, dnfile.stream.MetaDataTables):
num_tables = len(s.tables_list)
Verify before relying
- Whether the package handles all .NET Framework versions and modern .NET Core/5+ formats equally well
- Performance characteristics when parsing very large binaries or deeply nested resource hierarchies
Package facts
| License | MIT License permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packagepefile |
| Maintenance | Actively maintained 195 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 289,581 / month, #7,999 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9 |
Evidence: dnfile-0.18.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “.NET executable parsing”
- dnfileParses .NET executable files to extract and inspect CLR metadata,…
- dncildncil is a Python library for disassembling Common Intermediate…
- serpentSerpent serializes Python objects to human-readable, safe literals…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also dncil · pefile · clr_loader · pyxbe · pythonnet · pylnk3 · pyinstxtractor-ng · lief · signify · codespell