π File Forensics
Inspect documents and packaged files down to their metadata, internal parts, relationships, embedded media, readable strings, signatures, entropy, and raw bytes. Supported edits are staged without overwriting the original file.
This tool is client-side only. Everything happens in your browser and none of your data is shared.
Overview
Document Properties
These fields are stored inside the file and can include creator, last editor, company, title, or timestamps. They are useful clues, but they are not authentication: software can rewrite them.
Package Anatomy
Choose an internal part to inspect it. ZIP/XML document formats are shown using their real internal paths.
Selected Part
Select an internal part to inspect its contents.
Content Clues
This view summarizes format-specific structures that can matter during inspection, including Word comments and revisions, spreadsheet formulas and hidden sheets, PowerPoint notes and hidden slides, EPUB navigation, and related package features.
Relationships & External References
Office Open XML relationship files connect documents to images, hyperlinks, templates, embedded objects, and other parts. External relationships can point outside the file.
Embedded Media & Objects
Images, audio, video, fonts, and embedded documents found inside supported packages appear here.
Printable Strings
This scans the raw file for readable text that can expose software names, URLs, identifiers, XML fragments, and other material not surfaced by the normal parser. A readable string shows that those bytes exist; it does not prove what created the file.
Raw Hex
Each hexadecimal pair represents one byte. The left side is the byte offset, the middle is hexadecimal, and the right is a printable ASCII interpretation. Raw edits can intentionally make a file invalid, so changes are staged separately.
Pending Changes
Structured edits and raw-byte changes are staged here. The uploaded file remains untouched until you build a modified copy.
Export & Report
ZIP/XML packages can be rebuilt after supported internal-text or property edits. Raw-byte edits operate directly on a copy of the original byte stream. Structured edits and raw-byte edits cannot be mixed in the same build. Generated output is reparsed where possible before download.
Verification
About This Tool
File Forensics is a document and file analysis tool for inspecting the internal structure of Office documents, PDFs, ZIP archives, OpenDocument files, EPUBs, RTF files, legacy Office formats, and arbitrary binary files. It identifies file types from their contents and exposes the data stored beneath the normal document view.
For package-based formats such as DOCX, XLSX, PPTX, ODT, and EPUB, the tool opens the package and lists its internal files, XML, document properties, relationships, embedded media, and supporting data. PDF, ZIP, and OLE files receive additional structural analysis suited to their container formats.
File Forensics can also examine printable strings, SHA-256 hashes, timestamps, hidden or appended data, entropy, embedded file signatures, and raw hexadecimal bytes. These views are useful for finding material that ordinary document software does not display.
Supported fields and internal parts can be edited or removed, and individual byte changes can be staged in the hex editor. The original file remains available while changes are reviewed and a modified file or forensic report is prepared for export.