REDMARK FORGE SANDBOX
Inspect · Verify · Compare

Digital Forensics Studio

Browser-local file triage: identify signatures, inspect bytes, extract printable strings, estimate entropy, detect common trailing markers, hash evidence and compare samples.

Scope: educational triage, not a forensic acquisition suite or malware verdict. Preserve originals and document provenance. Entropy and signature rules are indicators, not proof. Detailed inspection is limited to 128 MiB per file.

01 · Evidence intake & inventory

Multiple files supported; drag and drop, batch inventory, CSV export.

No files selected.
Choose evidence to begin.

02 · Identity, entropy & cryptographic digests

SHA-256/SHA-384/SHA-512, entropy, extension mismatch and file facts.

Size—
Entropy—
Signature—
SHA-256—
SHA-384—
Extension—

03 · Hex viewer & exact byte search

Offset-addressed hex/ASCII view; search hex signatures and export a selected region.

Analyze a file to inspect bytes.
Exact byte search; first 1000 hits maximum.

04 · Printable strings & structure

Extract ASCII runs and inspect common EOF/end markers for trailing bytes.

Printable strings appear with byte offsets.

Structure / trailing-data indicators

Analyze a file to scan markers.

05 · Evidence comparison

Byte equality, digest comparison, aligned differing positions and length delta.

Select two samples.

06 · Embedded-file carving

Scans the whole evidence file for 40+ file signatures at any offset, validates headers, estimates extent (exact for PNG, JPEG, GIF, BMP, RIFF, SQLite, MP4; heuristic otherwise) and exports carved regions or all of them as a ZIP.

Choose a file in panel 01, then scan.

07 · Entropy map & byte histogram

Block-by-block Shannon entropy across the file reveals compressed/encrypted regions, padding and appended data. Hover the chart for offsets.

Hover for offset and entropy.
Choose a file in panel 01, then draw.
High-entropy and low-entropy regions are listed here.

08 · Indicators of interest (IOC) extractor

Pulls URLs, e-mails, IPv4 addresses, domains, Windows paths, registry keys, hashes, JWTs and Base64 blobs from ASCII and UTF-16LE strings.

Ready.
Indicators appear grouped by type with offsets.

09 · XOR & Base64 probe

Single-byte XOR brute force (scored by printable ratio, English letter frequency and known magic) plus repeating-key keysize estimation by Hamming distance.

Ready.
Uses the first 256 KiB of the selected file.

10 · Multi-hash lab & verifier

MD5, SHA-1, SHA-256, SHA-384, SHA-512 and CRC-32 for every selected file, duplicate detection across the batch, and a known-hash verifier that auto-detects the algorithm.

Ready.
Hash results and duplicate groups appear here.

11 · Case report

Bundles everything computed on this page (identity, carving, entropy regions, indicators, hashes) into one Markdown or JSON report.

Run any analysis above first; sections that have not been run are omitted.