Back to overview
Capability explained

Files, images and archives

These tools inspect files, images and ZIP archives without executing active content. They compare the filename, true format, metadata and technical warning signs.

What can be examined?

  • File signature, extension, size and SHA-256
  • EXIF, XMP and IPTC metadata including GPS
  • Embedded Python, JavaScript, PowerShell or shell source
  • PDF actions, Office macro indicators and external relationships
  • Media containers and possible steganography indicators
  • Every regular file in a safely limited ZIP archive
  • Known malware signatures with ClamAV

What can you find out?

  • When and with which software metadata says a file was created
  • Whether an image discloses coordinates or device details
  • Whether the extension disguises the content
  • Whether active or embedded source code is present
  • Whether the scanner reports a known signature

Example from journalistic work

A press image contains GPS data and JavaScript in a PNG text field. Both are shown separately. The coordinate is a lead; the code is a warning and is never executed.

What does the result not prove?

  • Metadata can be removed or forged.
  • Embedded source is not automatically executable or malicious.
  • No scanner or steganography finding is not proof of safety.

Evidence and privacy

Only tools actually used and their inputs are recorded. Results, sources, timestamps, hashes and embedded evidence remain attributable. External services are only contacted where the tool expressly states this.

New book, new blog post? Be the first to know!

Sign up and get notified when a new book, blog post or podcast episode is published.

Notify me about

Files, images and archives | Forensics & OSINT