← Back to overview
Capability explained
Files, images and archives
These tools inspect files, images and ZIP archives without executing active content. They compare the filename, true format, metadata and technical warning signs.
What can be examined?
- File signature, extension, size and SHA-256
- EXIF, XMP and IPTC metadata including GPS
- Embedded Python, JavaScript, PowerShell or shell source
- PDF actions, Office macro indicators and external relationships
- Media containers and possible steganography indicators
- Every regular file in a safely limited ZIP archive
- Known malware signatures with ClamAV
What can you find out?
- When and with which software metadata says a file was created
- Whether an image discloses coordinates or device details
- Whether the extension disguises the content
- Whether active or embedded source code is present
- Whether the scanner reports a known signature
Example from journalistic work
A press image contains GPS data and JavaScript in a PNG text field. Both are shown separately. The coordinate is a lead; the code is a warning and is never executed.
What does the result not prove?
- Metadata can be removed or forged.
- Embedded source is not automatically executable or malicious.
- No scanner or steganography finding is not proof of safety.
Evidence and privacy
Only tools actually used and their inputs are recorded. Results, sources, timestamps, hashes and embedded evidence remain attributable. External services are only contacted where the tool expressly states this.