Why an MSI is not a ZIP file
An .msi is a Compound File Binary container โ the same format as an old .doc
โ holding a relational database of installation instructions. Tables inside it describe every file,
registry key, shortcut and condition the installer applies. The files themselves are usually not stored
loose: they sit in one or more CAB cabinets embedded as streams in the same container.
That is why generic unzip tools fail on an MSI. There is no ZIP directory to read. This tool walks the Compound File structure directly โ header, allocation table, directory, then each stream, including the mini-allocation table used for streams under 4 KB.
For a complete inventory of every file and registry key an MSI typically carries, read what is inside an MSI file.
How to extract an MSI file online
- Open the package. Drop the .msi onto the box above, or click to browse. The Compound File structure is read locally in your browser.
- Read the package details. Product name, manufacturer, package code, target platform and language, build tool and creation date all come from the package's SummaryInformation stream.
- List the files inside. Open the Files inside tab to see every file in the installer's CAB payload, with its size and date, before installing anything.
- Save the payload. Save the embedded CAB, then open it with 7-Zip or Windows Explorer, both of which read CAB natively.
What the extractor reads
- Product name and manufacturer, plus title, comments and keywords, from the package's SummaryInformation stream.
- Package code โ the GUID that uniquely identifies this exact build, which is what deployment tools key on.
- Target platform and language, for example
Intel;1033for 32-bit English orx64;1033for 64-bit. - Build details โ the tool that produced the package, its schema version, and the creation and last-saved timestamps.
- The CAB payload โ every embedded cabinet is detected, its file index listed with names, sizes and dates, and the cabinet itself saved on request.
- Every database stream, with Microsoft's name obfuscation decoded back into readable table names, each one savable individually.
Supported packages
.msi packages are the primary target. .msp patches, .msm merge
modules and .mst transforms use the same Compound File format and open the same way, though
they carry different tables.
Both 512-byte and 4096-byte sector layouts are handled, which covers every package Windows Installer produces. Packages up to 512 MB open; above that the tool stops rather than exhausting browser memory.
Why the package is never uploaded
The Compound File structure is parsed by JavaScript in your browser. No server takes part, so the package is never transmitted and nothing survives closing the tab.
This matters for MSIs specifically. Enterprise packages are frequently repackaged in-house and contain licence keys, internal server names, service account references and configuration baked into their property tables. Uploading one to an inspection website hands all of that to a third party.
What this tool does not do
Three boundaries, stated plainly:
- It does not decompress the CAB payload. CAB files use MSZIP or LZX compression, neither of which a browser can decode. The files are listed by name, size and date; the cabinet is saved for you to open with 7-Zip.
- It does not decode the full installer database. Reading the File, Directory, Registry and Property tables requires resolving the package's internal string pool and column definitions. Streams are listed and downloadable, but their table contents are not parsed into readable rows.
- It does not install, modify or repackage anything. This is a reader.
To extract an MSI's files properly on Windows, run
msiexec /a package.msi /qb TARGETDIR=C:\out, which performs an administrative install and
writes the real file tree.
Who inspects MSI packages
- Deployment and SCCM administrators โ reading the package code and product version before publishing a package to a fleet.
- Software auditors โ recording exactly what an installer claims to be and what it contains.
- Security reviewers โ checking the manufacturer, build tool and file list of a package from an unfamiliar source before letting it near a machine.
- Support engineers โ confirming which build a user actually installed.
- Packagers โ verifying that a freshly built MSI carries the metadata and files it should.
MSI packages compared with EXE installers
An MSI is a database consumed by Windows Installer, which handles installation, repair and uninstall centrally. An EXE installer is a program that installs software however its author chose. Many downloads are an EXE bootstrapper that unpacks and runs an MSI.
For an .exe, use the EXE extractor, which reads the
executable's metadata, signature and any embedded payload. If the package turns out to hold a plain
archive, the ZIP extractor opens it. If you only want the program's icon,
the icon extractor is the direct route.
MSI format internals and extraction edge cases
A Windows Installer (.msi) file is a Compound File Binary Format (CFBF) container โ
the same format used by .msg files. Inside, database tables are stored as CFBF streams with
names encoded using a proprietary scheme. The binary payload is in the
_Streams table or in a Cabinet (CAB) archive referenced by the
Media table.
Three edge cases: (a) a compressed MSI stores its CAB file as a stream in the
_Streams table โ the extractor reads that CAB stream and lists the installation
files it contains; (b) transform files (.mst) patch the MSI's table data at install time
but are separate files โ the extractor reads the base MSI, not any applied transforms;
(c) merge modules (.msm) share the MSI format but lack a Product GUID and cannot be
installed directly โ they are intended to be merged into MSI packages at build time; the
extractor reads and lists their contents identically to a regular MSI. For a complete breakdown of what is inside an MSI file, including the Property, File and Registry tables, see the guide.
Frequently asked questions
Can I extract an MSI file online?
Yes. Drop it above to read its product details, list the files in its CAB payload and save that payload. Full decompression of the CAB needs 7-Zip, because browsers cannot decode MSZIP or LZX.
How do I extract files from an MSI without installing it?
On Windows, run msiexec /a package.msi /qb TARGETDIR=C:\out for an administrative install, which writes the real file tree. Alternatively save the CAB from this tool and open it with 7-Zip.
Why can't I just unzip an MSI?
An MSI is a Compound File database, not a ZIP archive. It has no ZIP directory, so unzip tools find nothing to read.
Is my MSI uploaded to a server?
No. The package is parsed inside your browser and is never transmitted.
What is the package code?
A GUID identifying this exact build of the package. Deployment systems use it to tell one build from another, even when the product name and version are unchanged.
Why does my package show no embedded CAB?
Its files are stored uncompressed alongside the .msi, or shipped as separate external .cab files. Check the folder the .msi was downloaded in.
What are the obfuscated stream names?
Windows Installer encodes table names into a private character range so they cannot collide with normal stream names. This tool decodes them back, so you see File and _StringData rather than unreadable characters.
Does it work on macOS or Linux?
Yes. Parsing happens in the browser, so Windows packages can be inspected from any operating system.