Skip to content

Repository files navigation

Entropy Analyzer

Native Windows folder entropy analysis tool built with C++17 and WUI.

Screenshot

Features

  • Recursive folder scanning with Shannon entropy, chi-square distribution, printable byte ratio, zero-byte ratio, and RLE compression score per file
  • Three scan depths: Level 1 (top-level only), Level 2 (recursive), Level 3 (deep)
  • Large-file divide-and-sample strategy: head, middle, and tail blocks
  • File type detection: archive, encrypted, media, document, executable, and more
  • Five-tier classification: Suspicious → Review → Expected High → Normal → Error
  • GPU detection via DXGI, showing adapter name and dedicated video memory
  • Result filtering by status, file type, and entropy range
  • CSV export of the currently filtered result set
  • Capped at 5,000 visible rows for responsiveness; CSV export includes all filtered rows

Build

Prerequisites

  • Visual Studio 2022+ or MinGW-w64
  • CMake 3.20+
  • Windows SDK 10.0+

CMake

cmake -B build -S .
cmake --build build --config Release

PowerShell script

.\build_wui.ps1

Usage

.\build-wui-manual\EntropyAnalyzerWui.exe
  1. Click Browse... to select a target folder
  2. Choose a scan depth (Level 1/2/3)
  3. Click Scan to start
  4. Use the dropdowns and input fields to filter results
  5. Click Export CSV to save the filtered results

Algorithms

The scanner combines multiple signals rather than relying on entropy alone:

Metric Description
Shannon Entropy Information entropy of byte distribution (0–8)
Chi-Square Distance from uniform byte distribution
Printable Ratio Fraction of printable ASCII characters
Zero Ratio Fraction of zero bytes
RLE Score Run-length encoding compression score

Known compressed, encrypted, and media formats (e.g. .zip, .png, .mp4) are classified as Expected High. Unknown file types with high entropy and random-like distribution are flagged as Suspicious.

Project Structure

EntropyAnalyzer/
├── src/                    # Application source
│   ├── Main.cpp            # WUI interface entry point
│   ├── EntropyCore.cpp     # Entropy calculation core
│   ├── EntropyCore.h       # Data structures
│   └── entropy_wui.rc      # Windows resource file
├── thirdparty/
│   └── wui/                # WUI framework library
├── CMakeLists.txt
├── build_wui.ps1           # Build script
├── screenshot.png
└── README.md

License

Boost Software License 1.0. The bundled WUI library is also BSL-1.0 licensed.

About

Native C++/WUI folder entropy analyzer.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages