What Hexonaut Actually Is
Hexonaut is a hex editor and binary analysis tool designed for reverse engineering, firmware modification, and low-level data inspection. It's not the most flashy option on the market, but it handles a lot of common workflows without requiring you to learn a new ecosystem. I've used it for basic ROM hacks, patching game binaries, and reading raw memory dumps. It supports multiple file types — executables, ROMs, disk images, firmware blobs — and includes features like pattern searching, string extraction, and basic byte manipulation. The interface is functional rather than pretty. You open a file, you see hex on the left and ASCII on the right, and you edit from there.
Downloading and Installing Hexonaut
You can find the latest version at hexonaut.io. The site offers Windows, macOS, and Linux builds. Grab the installer that matches your architecture — they provide both 64-bit and ARM64 variants now. During installation, it doesn't bundle adware or toolbars, which is unusual enough that I noted it. Once installed, launch it and go to File > Open. From there you can load any binary file up to several gigabytes without issues, though performance degrades noticeably past about 2GB on older hardware.
How It Works Under the Hood
Hexonaut reads files directly into a virtual memory-mapped buffer rather than loading everything into RAM at once. This is the main reason it handles large files decently. When you make edits, it writes to a temporary staging file first, then replaces the original only after you explicitly save. That's actually a safety net — I've recovered work before by clearing the staging directory when I messed up an edit I hadn't saved yet. The search engine uses Boyer-Moore style matching for byte sequences, which is fast. String searches scan the ASCII decoder output rather than doing full Unicode normalization, so expect inconsistencies if you're looking for multibyte character sets. It found what I needed for ASCII-heavy Chinese texts in ROMs, but Japanese shift-JIS strings sometimes returned partial hits.
Practical Workflow
Here's how I typically use it in a real project. Open the binary. Use Edit > Find > Hex Value to locate a known constant. Say you're patching a damage multiplier in a retro game — you'd search for the float or integer value you expect, maybe with some tolerance using wildcards. Once found, cross-reference nearby strings to confirm you're in the right area. Make your edit. Save to a new file and test it in the emulator. If it crashes, you know you modified something structural rather than a standalone value. The bookmark feature is genuinely useful here. You can mark addresses, label them, and come back to them later. I keep a text file of my bookmark coordinates so I can reload sessions across different projects.
A Real Problem I Hit
I was working on a custom firmware dump one time and noticed that certain memory regions reported as unreadable even though I knew the data existed. Hexonaut was returning "Access Denied" on specific page boundaries. Turns out the file had non-standard alignment padding that confused the internal offset calculator. The workaround was straightforward: I opened the file in a different hex editor (HxD), noted the exact offset where the issue started, then in Hexonaut I used View > Jump to Offset and entered the value manually. It loaded the region fine from that point onward. The issue seems tied to how Hexonaut interprets sparse file allocations versus actual zero-filled regions. It's a minor bug. It happens rarely. But when it does, you're stuck unless you know to jump directly to the offset.
Common Pitfalls to Avoid
First, don't assume the disassembly view is trustworthy for anything beyond x86_64. The built-in disassembler is basic and doesn't handle custom instruction sets or ARM thumb mode well. If you need proper disassembly, export the bytes and use Ghidra or radare2 instead. Hexonaut's disasm is a convenience feature, not a replacement. Second, the auto-highlight feature for repeated patterns can be misleading. It marks repeating byte sequences regardless of whether they're meaningful data or just coincidental padding. I once spent twenty minutes trying to figure out a "pattern" that turned out to be uninitialized stack memory in a crash dump. Disable auto-highlight if you're doing serious analysis. Third, save often to a new filename. The undo stack holds roughly 500 actions before it starts dropping older entries. That's enough for small patches but insufficient for extended reverse engineering sessions where you might make thousands of edits across a multi-hour session.
Where Hexonaut Falls Short
It doesn't support scripts or macros. If you need to automate repetitive patches across multiple files, you're out of luck. It also lacks a proper graph viewer for control flow analysis. For anything beyond basic byte editing and searching, you'll want to pair it with other tools. The plugin system is nonexistent. There's no way to extend functionality through community contributions, which means bugs stick around longer than they should and niche features never get added. If you're doing serious reverse engineering day-to-day, I'd recommend keeping a Ghidra orIDA license alongside Hexonaut. It's not a problem for occasional use, but the limitations become painful quickly at scale.
Who Should Use It
Hexonaut works well for hobbyists modding retro games, embedded developers who need a quick look at firmware dumps, or anyone who needs a lightweight hex editor that won't slow down on medium-sized files. If you're a professional reverse engineer or security researcher, it's a supplementary tool at best. For the price — it's free — it does what it claims without pretense. Don't expect it to replace specialized tools, but for quick edits, pattern searches, and byte-level inspection, it gets the job done without friction.