Neatbo.

Signature hints do not prove whole-file validity

A bounded signature can suggest a type while unread regions, format validity and safety remain unknown.

Extensions, signatures and complete contents are different evidence

The author discusses type clues for recovered files and data/unknown interpretation. Directory recovery, bulk renaming, validity and market scale are outside this claim.

Unknown, empty, incomplete, extension mismatch and multiple visible signatures are explicit outcomes. A matched signature, library clue or declared-size check does not prove the whole file is valid, safe or openable. Not all polyglots are detectable.

Keep each kind of evidence separate
EvidenceWhat it contributesWhat remains unproved
Filename extensionA name to compare with detected hintsActual format or valid contents
Visible signature and library clueA bounded type candidate with recorded evidenceWhole-file validity, safety or openability
Several visible candidatesAll detected candidates and any conflictsA unique format or complete polyglot detection
Unknown resultNo supported recognition from this sampleThat the original is corrupt or useless

Keep multiple visible hints together

One original can expose an image header, ftyp brand or ZIP footer together. The report preserves all hints visible to this profile, including declared-size conflicts, instead of forcing one format.

Retain originals before choosing the next step

ZIP and GZIP hints do not decompress contents, identify Office subtypes or inventory entries. Audio, images and executable bodies are not fully parsed, decoded or executed. Files are not renamed or repaired.

Reduce the selection or adjust a copy’s name if limits are exceeded; reselect originals after a read error. Retry the same files after cancellation or timeout. Unknown is an honest bounded-sample result; do not guess an extension or execute the file.

  • Keep the original filename and bytes while investigating a hint.
  • Read the exact sampled ranges and preserve every candidate in the complete report.
  • Use an appropriate format-aware checker or trusted application for the next inspection; this report does not perform that step.

References

  • First-person extensionless-file question

    The author discusses type clues for recovered files and data/unknown interpretation. Directory recovery, bulk renaming, validity and market scale are outside this claim.

Tools in this category

Expand a tool to see its steps, options and supported formats, then open its workspace.

File signature type hintsCheck common signatures, filename relations and explicit unknown results from bounded local file samples; download the complete evidence JSON.

Check common signatures, filename relations and explicit unknown results from bounded local file samples; download the complete evidence JSON.

Steps

  1. Select the original local files, including missing or incorrect extensions.
  2. Build the report and review unknown, incomplete, multiple-hint and extension-relation outcomes per file.
  3. Use the exact read ranges to identify unexamined regions; a signature is not a validity check.
  4. Copy the complete JSON or download file-signature-hints.json. Retain the originals and retry after cancellation.

Capabilities and limits

  • Select 1–100 original local files of any extension. Each filename is limited to 512 UTF-16 units; the original file size must be a nonnegative safe integer. Pasted text is not a file source.
  • The report gives hints for PNG, JPEG, GIF, WebP, PDF, ZIP, GZIP, WAV, Ogg, FLAC, MP4-brand ISO BMFF, ELF and PE. These are one identification task; other types can remain unknown or appear only as an extra library diagnostic.
  • For each file, read at most the first 8,192 bytes and the last 65,536 bytes without overlap. The original size and exact read ranges remain in the report. Any middle gap is unexamined; large originals are not fully loaded or hashed.
  • Unknown, empty, incomplete, extension mismatch and multiple visible signatures are explicit outcomes. A matched signature, library clue or declared-size check does not prove the whole file is valid, safe or openable. Not all polyglots are detectable.
  • ZIP and GZIP hints do not decompress contents, identify Office subtypes or inventory entries. Audio, images and executable bodies are not fully parsed, decoded or executed. Files are not renamed or repaired.
  • All rows and evidence are delivered in file-signature-hints.json (application/json), up to 1 MiB. The screen previews the first 4,000 Unicode code points; copy and download preserve the complete compact UTF-8 JSON.
  • The maximum sampled read for 100 files is 7,372,800 bytes, below the 8 MiB guard. The fixed-schema complete JSON bound is 521,804 bytes, below 1 MiB; neither guard is an independent reachable capacity edge.
  • A 60-second deadline covers preparation, reads, Worker loading and processing. Cancel or timeout settles immediately, stops further sampling and terminates any Worker. No partial report is delivered; the original selected files remain available for retry. File contents and names are not uploaded.
Open File signature type hints →