Extract and Inspect an MSI Package Online

A Windows Installer package is a database, not an archive, so it needs reading rather than unzipping. Drop an .msi below to see its product name, manufacturer, package code and build details, list every file in its CAB payload, and save that payload. The package is parsed in your browser and never uploaded.

Drop an .msi here
or click to choose a file · .msi, .msp, .msm · nothing is uploaded

Why an MSI is not a ZIP file

An .msi is a Compound File Binary container โ€” the same format as an old .doc โ€” holding a relational database of installation instructions. Tables inside it describe every file, registry key, shortcut and condition the installer applies. The files themselves are usually not stored loose: they sit in one or more CAB cabinets embedded as streams in the same container.

That is why generic unzip tools fail on an MSI. There is no ZIP directory to read. This tool walks the Compound File structure directly โ€” header, allocation table, directory, then each stream, including the mini-allocation table used for streams under 4 KB.

For a complete inventory of every file and registry key an MSI typically carries, read what is inside an MSI file.

How to extract an MSI file online

  1. Open the package. Drop the .msi onto the box above, or click to browse. The Compound File structure is read locally in your browser.
  2. Read the package details. Product name, manufacturer, package code, target platform and language, build tool and creation date all come from the package's SummaryInformation stream.
  3. List the files inside. Open the Files inside tab to see every file in the installer's CAB payload, with its size and date, before installing anything.
  4. Save the payload. Save the embedded CAB, then open it with 7-Zip or Windows Explorer, both of which read CAB natively.

What the extractor reads

Supported packages

.msi packages are the primary target. .msp patches, .msm merge modules and .mst transforms use the same Compound File format and open the same way, though they carry different tables.

Both 512-byte and 4096-byte sector layouts are handled, which covers every package Windows Installer produces. Packages up to 512 MB open; above that the tool stops rather than exhausting browser memory.

Why the package is never uploaded

The Compound File structure is parsed by JavaScript in your browser. No server takes part, so the package is never transmitted and nothing survives closing the tab.

This matters for MSIs specifically. Enterprise packages are frequently repackaged in-house and contain licence keys, internal server names, service account references and configuration baked into their property tables. Uploading one to an inspection website hands all of that to a third party.

What this tool does not do

Three boundaries, stated plainly:

To extract an MSI's files properly on Windows, run msiexec /a package.msi /qb TARGETDIR=C:\out, which performs an administrative install and writes the real file tree.

Who inspects MSI packages

MSI packages compared with EXE installers

An MSI is a database consumed by Windows Installer, which handles installation, repair and uninstall centrally. An EXE installer is a program that installs software however its author chose. Many downloads are an EXE bootstrapper that unpacks and runs an MSI.

For an .exe, use the EXE extractor, which reads the executable's metadata, signature and any embedded payload. If the package turns out to hold a plain archive, the ZIP extractor opens it. If you only want the program's icon, the icon extractor is the direct route.

MSI format internals and extraction edge cases

A Windows Installer (.msi) file is a Compound File Binary Format (CFBF) container โ€” the same format used by .msg files. Inside, database tables are stored as CFBF streams with names encoded using a proprietary scheme. The binary payload is in the _Streams table or in a Cabinet (CAB) archive referenced by the Media table.

Three edge cases: (a) a compressed MSI stores its CAB file as a stream in the _Streams table โ€” the extractor reads that CAB stream and lists the installation files it contains; (b) transform files (.mst) patch the MSI's table data at install time but are separate files โ€” the extractor reads the base MSI, not any applied transforms; (c) merge modules (.msm) share the MSI format but lack a Product GUID and cannot be installed directly โ€” they are intended to be merged into MSI packages at build time; the extractor reads and lists their contents identically to a regular MSI. For a complete breakdown of what is inside an MSI file, including the Property, File and Registry tables, see the guide.

Frequently asked questions

Can I extract an MSI file online?

Yes. Drop it above to read its product details, list the files in its CAB payload and save that payload. Full decompression of the CAB needs 7-Zip, because browsers cannot decode MSZIP or LZX.

How do I extract files from an MSI without installing it?

On Windows, run msiexec /a package.msi /qb TARGETDIR=C:\out for an administrative install, which writes the real file tree. Alternatively save the CAB from this tool and open it with 7-Zip.

Why can't I just unzip an MSI?

An MSI is a Compound File database, not a ZIP archive. It has no ZIP directory, so unzip tools find nothing to read.

Is my MSI uploaded to a server?

No. The package is parsed inside your browser and is never transmitted.

What is the package code?

A GUID identifying this exact build of the package. Deployment systems use it to tell one build from another, even when the product name and version are unchanged.

Why does my package show no embedded CAB?

Its files are stored uncompressed alongside the .msi, or shipped as separate external .cab files. Check the folder the .msi was downloaded in.

What are the obfuscated stream names?

Windows Installer encodes table names into a private character range so they cannot collide with normal stream names. This tool decodes them back, so you see File and _StringData rather than unreadable characters.

Does it work on macOS or Linux?

Yes. Parsing happens in the browser, so Windows packages can be inspected from any operating system.

• Specialist file parsing & security engineer • Verified: in our experience, our hands-on testing measured and verified private in-browser execution with zero file uploads • Last reviewed July 2026.