← Все инструменты
BROWSER · Toolardo passive PDF inspection engine · first-party JavaScript

Анализатор безопасности PDF

Локально проверяйте действия, JavaScript, внешние ресурсы, вложения и аномалии PDF без рендеринга и загрузки файла.

✓ Приватность по умолчанию✓ Работает на вашем устройстве✓ Бесплатно · Без регистрации
PASSIVE • LOCAL • EVIDENCE-FOCUSED

PDF Security Analyzer

Inspect PDF attack surface without opening, rendering or uploading the document.

Never renderedStatic analysisNo upload

This scanner reads the file locally and never embeds it in a PDF viewer.

Об этом инструменте

PDF Security Analyzer is a passive browser-based static inspection tool. It checks raw PDF bytes and safely decoded streams for high-risk actions, script indicators, remote resources, embedded content and structural anomalies without opening the document in a PDF renderer.

Common uses
Анализатор безопасности PDF onlinefree Анализатор безопасности PDF

Как это работает

  1. 1Choose one PDF file. The scanner reads bytes locally and verifies the PDF header before analysis.
  2. 2Run passive analysis to inspect actions, scripts, external references, embedded content, streams, encryption and structural anomalies.
  3. 3Review severity, evidence offsets and coverage warnings, then export a JSON, CSV or text report for further investigation.

Часто задаваемые вопросы

Does the analyzer open or execute the PDF?

No. It never embeds, renders or executes the document. It reads bytes and decompresses only supported, bounded streams for static inspection.

Does a LOW result prove that a PDF is safe?

No. Static browser analysis cannot prove safety or replace a maintained antivirus, sandbox or expert review. Encryption, unsupported filters, malformed objects and novel exploits can hide behavior.

Can a normal PDF contain flagged features?

Yes. Forms, links, embedded files and JavaScript can have legitimate uses. Findings describe attack surface and evidence; they are not by themselves a malware verdict.

What does the scanner look for?

It checks JavaScript and automatic-action markers, Launch/URI/GoTo/SubmitForm/ImportData actions, XFA and XML entities, embedded files, RichMedia, suspicious external or UNC paths, script network APIs, obfuscation indicators, encryption, object streams and data after the last EOF marker.

Похожие инструменты