Forensics collection
Binary inspection and forensics tools
Inspect bytes, files, metadata, executable structures, and embedded data.
Inspection explains observable structure. It does not prove that a file is trusted, complete, authentic, or safe to execute.
Browse the complete topic
This focused collection connects to the broader catalog categories.
22 tools
Working tools in this collection
- ARM DisassemblerDisassemble aRM into readable instructions. Add the content, choose the checks, and review the reported details.
- Audio Metadata ExtractorFind and collect audio Metadata from the supplied input. Add the content, choose the checks, and review the reported details.
- Bit Plane for View Binary InspectorInspect binary data with Bit Plane for View and review the recovered details. Add the content, choose the checks, and review the reported details.
- Bytes RemoverRemove bytes from the supplied data. Add the content, choose the checks, and review the reported details.
- Colour Palette RandomizerRandomize colour Palette with the selected options. Add the content, choose the checks, and review the reported details.
- ELF Info Binary InspectorInspect binary data with ELF Info and review the recovered details. Add the content, choose the checks, and review the reported details.
- Embedded Files ScannerScan the supplied data for embedded Files. Add the content, choose the checks, and review the reported details.
- EXIF ExtractorFind and collect eXIF from the supplied input. Add the content, choose the checks, and review the reported details.
- EXIF RemoverRemove eXIF from the supplied input. Add the content, choose the checks, and review the reported details.
- File Tree Binary InspectorInspect binary data with File Tree and review the recovered details. Add the content, choose the checks, and review the reported details.
- File Type DetectorDetect file Type in the supplied data. Add the content, choose the checks, and review the reported details.
- Files ExtractorFind and collect files from the supplied input. Add the content, choose the checks, and review the reported details.
- LSB ExtractorFind and collect lSB from the supplied input. Add the content, choose the checks, and review the reported details.
- nth bytes for Take Binary InspectorInspect binary data with nth bytes for Take and review the recovered details. Add the content, choose the checks, and review the reported details.
- Nth bytes RemoverRemove nth bytes from the supplied data. Add the content, choose the checks, and review the reported details.
- Offset checker Binary InspectorInspect binary data with Offset checker and review the recovered details. Add the content, choose the checks, and review the reported details.
- P-list Viewer Binary InspectorInspect binary data with P-list Viewer and review the recovered details. Add the content, choose the checks, and review the reported details.
- RGBA ExtractorFind and collect rGBA from the supplied input. Add the content, choose the checks, and review the reported details.
- Take bytes Binary InspectorInspect binary data with Take bytes and review the recovered details. Add the content, choose the checks, and review the reported details.
- UNIX file permissions ParserRead UNIX file permissions input and show its structured details. Add the content, choose the checks, and review the reported details.
- X86 DisassemblerDisassemble x86 into readable instructions. Add the content, choose the checks, and review the reported details.
- YARA Rules Binary InspectorInspect binary data with YARA Rules and review the recovered details. Add the content, choose the checks, and review the reported details.
Direct answers
Questions about this tool family
Can file inspection identify every format?
No. Truncated, encrypted, malformed, nested, or uncommon files can resist identification. Compare several independent indicators.
Is it safe to open an inspected file?
Not necessarily. Metadata and signatures can be missing or misleading. Use an isolated environment for untrusted executable content.
Continue the task