Skip to content
Tech News
← Back to articles

Reverse Engineering Unknown File Formats with ImHex

read original more articles
Why This Matters

This article highlights how ImHex, an open-source hex editor, simplifies reverse engineering of custom file formats, empowering developers and researchers to analyze and understand proprietary or unknown binary data. By demonstrating its application on a game save file, it underscores the tool's potential to unlock valuable insights across the tech industry and for consumers interested in modding or data recovery.

Key Takeaways

Over the years I’ve been asked the same question countless times:

Person on Discord asking for help reverse engineering a file format

I usually couldn’t really give them a good answer except, “Look at the decompiled code of whatever program reads/writes these files and work backwards from there.” This post is meant to change that. We’ll go from a completely custom binary save file for the game FEZ to a full definition written in the Pattern Language, which is part of ImHex, the hex editor I’ve been developing for the past few years. It is free, open source and available on any operating system (or even through the browser if you prefer that: ImHex Web).

ImHex Version At the time of writing, some features used here are not in a release yet but only available in the Nightly build (that can also be downloaded above from the same link). If you’re on ImHex v1.38.1 or below and experiencing issues, consider upgrading to the Nightly build

Spoiler Warning FEZ was released all the way back in 2012. Still, if you haven’t played it yet and want to get the full experience, I highly recommend playing it before you continue reading. Some of the code shown here will contain heavy spoilers for secrets and endgame content that might ruin your experience. You have been warned.

The first thing we need is the save file. I downloaded the game from Steam (the latest full release currently available, released 2. December 2016), started it and played for a little bit until it saved. Then I went looking through my filesystem and found the save file under /home/werwolv/.local/share/FEZ/SaveSlot2 . On Windows, it will be elsewhere.

Opening the file in ImHex shows this:

SaveSlot2 Hex View 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 00000000 3E 74 E1 41 6B BA DA 01 06 00 00 00 00 00 00 00 >t.Ak........... 00000010 3A AC 78 49 C9 B4 CF 01 01 00 01 00 00 01 12 00 :.xI............ 00000020 00 00 01 11 44 4F 54 5F 4C 4F 43 4B 45 44 5F 44 ....DOT_LOCKED_D 00000030 4F 4F 52 5F 41 00 01 10 44 4F 54 5F 4E 55 54 5F OOR_A...DOT_NUT_ 00000040 4E 5F 42 4F 4C 54 5F 41 00 01 0B 44 4F 54 5F 50 N_BOLT_A...DOT_P 00000050 49 56 4F 54 5F 41 01 01 11 44 4F 54 5F 54 49 4D IVOT_A...DOT_TIM 00000060 45 5F 53 57 49 54 43 48 5F 41 00 01 0F 44 4F 54 E_SWITCH_A...DOT 00000070 5F 54 4F 4D 42 53 54 4F 4E 45 5F 41 01 01 0C 44 _TOMBSTONE_A...D 00000080 4F 54 5F 54 52 45 41 53 55 52 45 00 01 0B 44 4F OT_TREASURE...DO 00000090 54 5F 56 41 4C 56 45 5F 41 01 01 13 44 4F 54 5F T_VALVE_A...DOT_

This already reveals a few things. The file seems to be uncompressed and unencrypted, as seen by the plain-text strings and other patterns in the file that can be easily spotted by just looking at the bytes and characters. The data also doesn’t have a file magic (some readable text at the start of the file to make it more easily identifiable), and it doesn’t look like anything standard, as ImHex can’t identify its type directly either.

Magic file information from ImHex

... continue reading