Static File Triage

Read one file in the browser, extract a bounded static fingerprint plus type and structure clues, then produce a share-safe summary for review.

FilesThe file page reads bytes selected from this device and does not execute them.

URLs and mailParsers inspect text and structure without opening the destination or performing DNS lookups.

ExportsDownloaded summaries keep findings and counts while omitting raw sensitive material.

Drag a file here, or click to choose

Supports any file type, up to 300 MB for local analysis.

Choose a file to start local analysis.

Local analysisOnly in the browser

No uploadFile does not leave device

No executionCode is not run

Privacy firstResults do not go out

Analysis Results waiting for file

Overview

File typeWaiting for file

Static signal countNot run

Size-

Entropy-

Arch-

Target OS-

Basic fields

Identity and format

Filename-

MIME-

Magic-

Extension / magic-

Hashes

SHA-256-

SHA-1-

MD5-

First 32 bytes-

Structure

Key counts and scope

ASCII strings-

UTF-16LE strings-

Indicators-

Analysis scopeBasic local fingerprint

Heuristics

Main judgement
Choose a file to start local analysissignals 0 / 12

Share-safe summary

File analysis

Organize a single local file first, then decide whether a separate authorized flow is needed.

Input
Single local file
Output
Hashes, type clues, indicator counts, share-safe summary
Boundary
No upload, no execution, no third-party request

Open file analysis

URL analysis

Inspect URL structure, IDN/Punycode, Safe Links, and defang/refang without visiting the target.

Input
URL or defanged URL
Output
Structure, IDN, Safe Links, sensitive keys, share-safe summary
Boundary
No target request or network validation

Open URL analysis

Email analysis

Parse headers or .eml text locally before moving links or observables into other tasks.

Input
Headers or .eml text
Output
Received chain, authentication header facts, links, share-safe summary
Boundary
No upload, no DNS verification

Open email analysis

IOC extraction

Extract observables from logs, alerts, and reports for clean handoff and review.

Input
Logs, alerts, reports
Output
Normalized observables, dedupe, defang/refang, redactions
Boundary
No third-party lookup; observations only

Open IOC extraction

Checksum comparison

Normalize hashes and compare checksums locally before sharing an investigation target.

Input
MD5/SHA values or checksum list
Output
Type detection, dedupe, expected/file/manifest compare
Boundary
No lookup by default

Open checksum comparison