Static File Triage

Read one file in the browser, extract a bounded static fingerprint plus type and structure clues, then produce a share-safe summary for review.

FilesThe file page reads bytes selected from this device and does not execute them.

URLs and mailParsers inspect text and structure without opening the destination or performing DNS lookups.

ExportsDownloaded summaries keep findings and counts while omitting raw sensitive material.

Drag a file here, or click to choose

Supports any file type, up to 300 MB for local analysis.

Choose a file to start local analysis.

Local analysisOnly in the browser

No uploadFile does not leave device

No executionCode is not run

Privacy firstResults do not go out

Analysis Results waiting for file

Overview

File typeWaiting for file

Static signal countNot run

Size-

Entropy-

Arch-

Target OS-

Basic fields

Identity and format

Filename-

MIME-

Magic-

Extension / magic-

Hashes

SHA-256-

SHA-1-

MD5-

First 32 bytes-

Structure

Key counts and scope

ASCII strings-

UTF-16LE strings-

Indicators-

Analysis scopeBasic local fingerprint

Heuristics

Main judgement
Choose a file to start local analysissignals 0 / 12

Share-safe summary

File analysis

Inspect file type, readable strings, and suspicious features.

Input
Single local file
Results
Hashes, file type clues, feature counts, redacted summary
Limits
Static inspection only; files are not executed

Open file analysis

URL analysis

Inspect domain spelling, Safe Links wrappers, and sensitive parameters in suspicious links.

Input
URLs, including hxxp and [.] notation
Results
Host and path, internationalized domains, unwrapped links, sensitive parameters
Limits
Does not open links or assess website reputation

Open URL analysis

Email analysis

Read delivery routes, authentication headers, and links in email text.

Input
Headers or .eml text
Results
Received route, recorded authentication results, links, redacted summary
Limits
Reads existing authentication records; no DNS verification

Open email analysis

IOC extraction

Find IPs, domains, URLs, email addresses, and hashes in large blocks of text.

Input
Logs, alerts, reports
Results
Grouped, deduplicated lists, defang/refang, redacted summary
Limits
An extracted address or hash is not necessarily malicious

Open IOC extraction

Checksum comparison

Check whether a file hash matches the checksum supplied by its publisher.

Input
MD5/SHA values, checksum lists, or local files
Results
Hash types, duplicates, file and manifest comparison results
Limits
Matching hashes do not establish file safety

Open checksum comparison