File forensics
The full reference for file metadata, true-type identification, and secret/indicator scanning — tool by tool, with inputs, outputs, and data source.
This category is for examining files you already have. You point a tool at a file and it tells you what is really inside — hidden metadata, true type, or secrets and indicators buried in it. Every tool here runs entirely on your machine: the file you're examining never leaves your computer.
| Tool | Input | Returns | Data source |
|---|---|---|---|
| Image Metadata | An image file | Format and dimensions, a curated EXIF tag subset, and any embedded GPS coordinates | Local |
| Office Metadata | An Office Open XML file (.docx, .xlsx, .pptx) | Author, organization, and revision metadata from the document | Local |
| PDF Metadata | A PDF | Metadata from its /Info dictionary and optional XMP packet — author, creator, dates, and more | Local |
| Tool | Input | Returns | Data source |
|---|---|---|---|
| File Signature | A file's leading bytes, pasted as hex or base64 | The file's true type identified from its magic bytes, regardless of extension, with notes on the format | Local |
| Reverse Image Search | An image URL | Ready reverse-image-search links across the major engines | Local |
| Tool | Input | Returns | Data source |
|---|---|---|---|
| Secret Scanner | Pasted text, or a local file path | Leaked credentials found in it — API keys, tokens, and similar secrets | Local |
| Data Extractor | Text, or a local file | Indicators of compromise pulled out of it — IPs, domains, hashes, and other markers | Local |
| Wordlist Extractor | A URL | Visible text from the page tokenized and filtered by length and character set into a usable wordlist | Live — fetches the target URL |