# ImHex: a hex editor that parses files with a C++-like pattern language

> ImHex is a C++ hex editor that attaches a C++-like pattern language, a node-based pre-processor and readers for disks, process memory and GDB targets to the byte grid. The documented surface is a desktop window, so unattended batch parsing is out of reach.

**WerWolv/ImHex** — ImHex is a hex editor for reverse engineers and programmers, with byte patching, patch management, unlimited undo/redo, and its own pattern language for binary analysis.

- Repository: https://github.com/WerWolv/ImHex
- Website: https://imhex.werwolv.net/
- Stars: 54,909 · Forks: 2,468
- Language: C++
- License: GPL-2.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/werwolv-imhex

## Patterns attach themselves by MIME type and magic value

ImHex ships a custom C++-like pattern language that parses and highlights a file's content instead of leaving raw bytes in the grid. Patterns load automatically when a file's MIME type or magic value matches, so opening a file can yield structured fields rather than a wall of hex. The language covers arrays, pointers, structs, unions, enums, bitfields, namespaces, little and big endian layout, and conditionals. A pattern can also drive visualization of images, audio, 3D models, coordinates, and time stamps. The editor reports useful error messages, highlights them, and marks the offending span. Version 1.38.0 shipped a Better Pattern Editor. The catch is that attachment depends on recognition, so a file whose header matches no known magic stays unparsed until you supply a pattern yourself.

## The node graph edits a view, not the file on disk

Before bytes reach the hex editor, they can pass through a node-based data pre-processor. Nodes modify, decrypt, and decode data, so what you see in the grid can be a decoded version of the underlying bytes rather than the bytes themselves. The pre-processor works without touching the underlying source, which makes it a place to unwrap an obfuscated or compressed blob before examining it. Custom nodes can be added, and the repository keeps them alongside the application code in the plugins directory, with a separate PLUGINS.md at the root. The consequence for the reader is that edits made through a transformed view do not map cleanly back onto the original file, so a byte changed in a decoded view is a patch to a value, not obviously to a stored byte.

## Data sources reach beyond a local file to live processes and remote servers

The data source list is where ImHex differs from a desktop-only hex editor. Local files are supported, including huge files with fast and efficient loading. Raw disks and partitions can be opened directly. A GDB Server connection reads the RAM of a running process or an embedded device over the GDB protocol, and a Process Memory source inspects the entire address space of a running process. Intel Hex and Motorola SREC data load as data, as does Base64 encoded data. Raw bytes arriving over UDP can be displayed, and files can be fetched from remote servers over SSH with SFTP. A paged data view keeps large inputs navigable. The tradeoff is that the first entry on that list is a local path, and everything after it needs a live target and credentials you supply.

## The Data Inspector reads 24-bit, 48-bit and LEB128 values

The Data Inspector is a separate panel that reinterprets the same bytes as many types, with endianness, decimal, hexadecimal, and octal display and a bit inversion option. Integers are covered at 8, 16, 24, 32, 48, and 64 bits, signed and unsigned. Floats come at 16, 32, and 64 bits. Signed and unsigned LEB128 are supported, along with ASCII, Wide, and UTF-8 characters and strings; time32_t, time64_t, and DOS date and time; GUIDs; and RGBA8 and RGB65 colors. Bytes can be copied and modified through the inspector, and new data types can be added through the pattern language. Unused rows can be hidden. The 24 and 48 bit rows and the LEB128 support are the ones missing from most simple inspectors.

## Search runs five ways, including numeric ranges

Searching covers the whole file or only the current selection, and there are five distinct modes. String extraction sets a minimum length and a character set drawn from lower case, upper case, digits, and symbols, and takes an encoding of ASCII, UTF-8, or UTF-16 in big or little endian. Sequence search looks for a run of bytes or characters with an option to ignore case. Regex search runs regular expressions over strings. Binary Pattern search matches byte sequences with optional wildcards. Numeric Value search finds signed and unsigned integers and floats, accepts a range of values, and lets you set size and endianness. Highlighting ties the results together: background highlighting can be driven by patterns, find results, and bookmarks, with configurable foreground rules on top.

## Export writes IPS, Base64, Markdown and language arrays

Import and export cover a short, explicit list. Base64 files can be read and written, as can IPS and IPS32 patches, which describe byte edits to an existing binary. Markdown reports can be produced, and data can be written out as binary arrays for various programming languages. The same set of formats appears in reverse for copying: bytes, hex string, C, C++, C#, Rust, Python, Java and JavaScript arrays, an ASCII-art hex view, and a self-contained HTML div. Two limits are visible here. No general binary diff or file comparison format appears anywhere in the import and export list, and the v1.38.1 release title lists Windows installer, data inspector edit and updater fixes, so those paths were recently changing.

## The documented entry points are windows, not a headless parser

Every documented way in is a window. The stable download sits at imhex.download, the nightly pre-release at imhex.download/#nightly, and a browser build runs at web.imhex.werwolv.net, with documentation at docs.werwolv.net. The repository root carries INSTALL.md, PLUGINS.md, SECURITY.md, and PRIVACY.md, and the tree separates cmake, lib, main, plugins, dist, resources, and tests directories. What none of that describes is a command line entry point, a headless mode, or a documented API for running a pattern over a file without a user present. If your plan is to parse a firmware dump inside a build script or a triage queue, the documented surface does not reach it, and you would be driving the graphical editor by hand.

## Master moves ahead of the tags

The repository is not archived and the last push on master is dated 2026-09-23, so commits are still landing. The tagged releases are further behind. v1.38.0 shipped 2025-12-06 with a Better Pattern Editor, new Data Sources, and Save Editor Mode, and v1.38.1 followed on 2025-12-21 with Windows installer, data inspector edit, and updater fixes. The build tagged nightly is dated 2025-08-09, which places it more than four months behind v1.38.1. Two consequences follow. The nightly pre-release link can hand you an older build than the current stable, and roughly nine months of master work sits outside any tag, so release notes will not tell you what changed in the default branch.

## Conclusion

ImHex suits an analyst who wants a file parsed into named fields instead of scanned as raw bytes, and who works interactively at a keyboard. It is a poor fit for unattended batch parsing, and it offers no built-in binary diff format. Before committing, check the version you will actually get: the nightly build is dated 2025-08-09, older than the v1.38.1 tag, and confirm the last push on master for anything newer.

## FAQ

### What is ImHex used for?

ImHex is a hex editor for reverse engineers and programmers. It adds a C++-like pattern language, a node-based pre-processor, a Data Inspector, and readers for raw disks, process memory, a GDB server, UDP packets, and files over SSH with SFTP.

### Is ImHex free?

The repository is licensed under GPL-2.0. A browser build is served at web.imhex.werwolv.net, and the maintainer lists GitHub Sponsors and Ko-Fi as optional ways to support the work.

### How to install ImHex?

The README points to imhex.download for the latest version and imhex.download/#nightly for the nightly pre-release, with a browser build at web.imhex.werwolv.net. The repository root carries an INSTALL.md, and documentation sits at docs.werwolv.net.

### imhex how to use patterns

Patterns load automatically from a file's MIME type and magic value, and they parse arrays, structs, unions, enums, bitfields, namespaces, endianness, and conditionals. New data types can also be added through the pattern language, and v1.38.0 shipped a Better Pattern Editor.

### is imhex safe

The repository ships SECURITY.md and PRIVACY.md, and the sponsor table credits SignPath with providing free code signing certificates for the Windows builds. ImHex can read raw disks, process memory and a GDB server, so it needs the permissions you grant it.

### Is ImHex good?

The last push to master is dated 2026-09-23 and the repository is not archived. The newest tag, v1.38.1, is dated 2025-12-21, and the build tagged nightly is dated 2025-08-09, so master runs well ahead of the tagged releases.

## Sources

- [Official documentation](https://imhex.werwolv.net/)
- [Official README](https://github.com/WerWolv/ImHex#readme)
- [Project repository](https://github.com/WerWolv/ImHex)
- [Release notes](https://github.com/WerWolv/ImHex/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/werwolv-imhex
