Digital Forensics Studio
Browser-local file triage: identify signatures, inspect bytes, extract printable strings, estimate entropy, detect common trailing markers, hash evidence and compare samples.
01 · Evidence intake & inventory
Multiple files supported; drag and drop, batch inventory, CSV export.
02 · Identity, entropy & cryptographic digests
SHA-256/SHA-384/SHA-512, entropy, extension mismatch and file facts.
03 · Hex viewer & exact byte search
Offset-addressed hex/ASCII view; search hex signatures and export a selected region.
04 · Printable strings & structure
Extract ASCII runs and inspect common EOF/end markers for trailing bytes.
Structure / trailing-data indicators
05 · Evidence comparison
Byte equality, digest comparison, aligned differing positions and length delta.
06 · Embedded-file carving
Scans the whole evidence file for 40+ file signatures at any offset, validates headers, estimates extent (exact for PNG, JPEG, GIF, BMP, RIFF, SQLite, MP4; heuristic otherwise) and exports carved regions or all of them as a ZIP.
07 · Entropy map & byte histogram
Block-by-block Shannon entropy across the file reveals compressed/encrypted regions, padding and appended data. Hover the chart for offsets.
08 · Indicators of interest (IOC) extractor
Pulls URLs, e-mails, IPv4 addresses, domains, Windows paths, registry keys, hashes, JWTs and Base64 blobs from ASCII and UTF-16LE strings.
09 · XOR & Base64 probe
Single-byte XOR brute force (scored by printable ratio, English letter frequency and known magic) plus repeating-key keysize estimation by Hamming distance.
10 · Multi-hash lab & verifier
MD5, SHA-1, SHA-256, SHA-384, SHA-512 and CRC-32 for every selected file, duplicate detection across the batch, and a known-hash verifier that auto-detects the algorithm.
11 · Case report
Bundles everything computed on this page (identity, carving, entropy regions, indicators, hashes) into one Markdown or JSON report.