Skip to content
Aback Tools Logo

DEX Bytecode Viewer

Upload a DEX (Dalvik Executable) file to view its bytecode structure, Dalvik instructions, opcodes, mnemonics, register usage, and method definitions. Parse the complete DEX structure including header fields, string tables, type/prototype/field/method tables, class definitions, and full instruction-level disassembly. Free, private, and no signup required.

DEX Bytecode Viewer
Upload a DEX (Dalvik Executable) file to view its bytecode structure, Dalvik instructions, method definitions, register usage, and more. All parsing is local and private.

Drop a DEX file here or click to browse

Supports .dex, .apk (extract classes.dex), and .odex files

Upload a DEX file to view its bytecode structure. The viewer parses the DEX header, string/type/proto/field/method tables, class definitions, and Dalvik bytecode instructions with full disassembly.

Why Use Our DEX Bytecode Viewer?

Complete DEX Structure Parsing

Parses the full DEX file format including header, string IDs, type IDs, prototype IDs, field IDs, method IDs, class definitions, and code items. View every structural element of your DEX file with raw offsets and sizes.

Full Dalvik Bytecode Disassembly

Disassembles Dalvik instructions into readable mnemonics with register operands, method references, type descriptors, and string constants. Supports all major instruction formats including 35c (invoke) and 3rc (invoke/range).

Class & Method Tree Explorer

Navigate classes and their methods in an expandable tree view. See access flags, superclass, interfaces, source file, register usage, and instruction-level bytecode for every method. Expand any class or method for full details.

100% Browser-Local & Private

All DEX parsing and disassembly runs entirely in your browser. Your DEX file, bytecode instructions, and parsed structure never leave your device. No uploads, no servers, no tracking - completely safe for analyzing any DEX file.

Common Use Cases for DEX Bytecode Viewer

Malware Analysis & Reverse Engineering

Analyze Android APK files for malicious behavior by examining Dalvik bytecode instructions. Identify suspicious API calls, obfuscated method names, and unusual control flow patterns directly in the bytecode - without needing to decompile to Java.

Security Auditing of Android Apps

Audit Android applications for security vulnerabilities by examining their bytecode. Look for insecure API usage, hardcoded credentials in the string table, improper permission checks, and unprotected component exports at the DEX bytecode level.

Obfuscation & Packer Analysis

Examine DEX files for obfuscation indicators such as unusual class/method names, reflection-heavy code, dynamically invoked methods, string encryption patterns, and class loader usage. The string table view helps identify encoded or encrypted payloads.

Android Development & Debugging

Android developers can examine compiled DEX output to verify ProGuard/R8 optimizations, check method inlining, understand how Kotlin features compile to bytecode, and debug compilation issues at the instruction level.

Forensic Analysis of Android Apps

Digital forensics analysts can examine DEX files from Android devices to understand app behavior, recover string constants and class structures, and build a complete picture of what an application does at the bytecode level.

Educational Study of Dalvik Bytecode

Learn how the Dalvik virtual machine works by exploring real DEX files. Understand instruction formats, register-based architecture, method dispatch, and type resolution. Perfect for students of Android internals and compiler design.

Understanding DEX Bytecode & Dalvik Instructions

What Is a DEX File?

A DEX (Dalvik Executable)file is the compiled bytecode format used by Android's Dalvik Virtual Machine and its successor ART (Android Runtime). Every Android application (.apk file) contains one or more classes.dex files that hold all the compiled Java/Kotlin code. Unlike standard JVM class files which use a stack-based architecture, DEX files use a register-based architecture where instructions operate on named virtual registers (v0, v1, etc.). This register-based design allows for more efficient bytecode interpretation and better performance on mobile devices. The DEX format was introduced with the Android platform in 2007 and has evolved through multiple versions (035, 037, 038, 039) with each version adding new opcodes and optimization features.

How Our DEX Bytecode Viewer Works

The DEX Bytecode Viewer parses the complete DEX binary format and disassembles Dalvik instructions in three stages, entirely in your browser:

  1. File upload and binary parsing: Upload a .dex file (or extract classes.dex from an .apk). The viewer reads the DEX header to locate all data sections and parses the string IDs, type IDs, prototype IDs, field IDs, method IDs, and class definitions using the standard DEX binary format specification.
  2. Bytecode disassembly: For each method that contains code, the viewer reads the code item structure (register count, argument count, instruction array) and disassembles each 16-bit instruction word. Each opcode is mapped to its Dalvik mnemonic (move, add-int, invoke-virtual, etc.), and operands are decoded based on the instruction format (12x, 35c, 3rc, etc.).
  3. Structured display: The parsed data is displayed in four views: Classes (expandable tree with methods and bytecode), Methods (flat table of all methods with prototypes), Strings (all string constants in the DEX file), and Header (full DEX header fields). Each instruction shows its offset, raw bytes, mnemonic, and decoded operands.

What You Can See in the DEX Structure

  • DEX Header: Magic number (dex\n035\0), checksum, SHA-1 signature, file size, section sizes and offsets for all data tables.
  • String Pool: All string constants used in the DEX file - class names, method names, field names, descriptor strings, and literal string values used in const-string instructions.
  • Type & Prototype Tables: Type descriptors (Ljava/lang/String;, I, [B, etc.) and method prototype definitions (return type + parameter types) that define method signatures.
  • Class Definitions: Every class in the DEX with access flags (public, abstract, interface, enum), superclass, interfaces, source file, and lists of direct and virtual methods.
  • Method Bytecode: Complete Dalvik instruction listings with register count, argument registers, try-catch blocks, and per-instruction disassembly showing offsets, opcodes, mnemonics, and decoded operands.

Privacy & Security

This tool runs entirely in your browser using client-side JavaScript. The DEX file you upload, all parsed bytecode, disassembled instructions, class structures, string tables, and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All parsing, disassembly, and display executes locally on your device. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it completely safe for analyzing proprietary Android applications, malware samples, or any sensitive DEX files.

Frequently Asked Questions About DEX Bytecode Viewer

A DEX (Dalvik Executable) file contains the compiled bytecode for Android applications. Viewing DEX bytecode lets you understand exactly what an app does at the instruction level - useful for malware analysis, security auditing, reverse engineering, debugging compilation issues, and learning how Android bytecode works.

Yes. Every Android APK contains a classes.dex file that the DEX Bytecode Viewer can parse. Extract classes.dex from any APK (using any ZIP extractor) and upload it. The viewer also accepts .odex (optimized DEX) files, though these may use additional opcodes specific to the optimized format.

The disassembler supports all major Dalvik instruction formats including 10x (no op), 11n (const/4), 12x (move), 21c (const-string), 21s (const/16), 22c (instance-of), 22t (branch), 23x (3-register), 35c (invoke), 3rc (invoke/range), 31i (const), 51l (const-wide), and many more. Over 200 opcodes are supported across all instruction categories.

No. The DEX Bytecode Viewer runs entirely in your browser. Your DEX file, all parsed data, disassembled instructions, and analysis results never leave your device. There are no server uploads, no API calls, and no data collection of any kind.

The viewer helps identify obfuscation by showing you the actual class/method names, string constants, and instruction patterns. Obfuscated DEX files typically have short meaningless names (a, b, c) visible in the class and method tables. Packed/protected DEX files may fail to parse if they use custom encryption or non-standard DEX format extensions.

The 35c format (used by invoke-virtual, invoke-direct, etc.) encodes up to 5 argument registers in a compact 16-bit field, with individual register numbers. The 3rc format (invoke-virtual/range, etc.) uses a range-based encoding where consecutive registers are specified by a start register and count. 3rc is used when there are many arguments or when arguments need to be in a specific contiguous range.

The String Table displays all string constants embedded in the DEX file. This includes class descriptors (Ljava/lang/String;), method and field names, type descriptors, source file names, and literal string values used in const-string instructions. Reviewing the string table is a quick way to understand what an app does - look for URLs, API endpoints, file paths, and other meaningful strings.

Yes. Methods with exception handling show try-catch block information including the start address, instruction count, and handler type (caught exception class or catch-all). Try-catch data appears below the instruction table when you expand a method with exception handlers.

Yes - 100% free with no signup, no account, and no usage limits. Parse as many DEX files as you need, as many times as you want. There are no premium tiers, hidden charges, or rate limits. All parsing runs in your browser.