DocScan — Document Security Analyser
A free, browser-based tool that scans documents, archives, binaries and network captures for macros, exploits, embedded secrets, and format spoofing. This app requires JavaScript and WebAssembly — please enable them to use it.
What it checks
- PDF, DOCX, XLSX and PPTX for macros, embedded objects, and active content
- Archives (ZIP, TAR, GZIP, BZIP2, XZ, 7-Zip, RAR) recursively, up to 5 levels deep
- Config and credential files (.env, AWS/GCP/Azure credentials, kubeconfig) for exposed secrets
- PE (EXE/DLL) and ELF binaries for suspicious imports and structure
- PCAP/PCAPNG network captures for TLS/JA3, DNS, HTTP and cleartext credentials
- Any file for a renamed or spoofed file type, by checking real byte signatures
All analysis happens locally in your browser — file contents are never uploaded to a server.