Skip to content
SHIFTby Guruge
All work

Cybersecurity / Digital Forensics 2026

Forensic File Analyzer

A learning project in digital forensics: upload a file and read its hashes, signature, entropy, strings and heuristic indicators.

Year
2026
Status
Learning project
Platform
Web · API
Scope
Web application, Analysis API
analyzer / pipeline
  1. 01UploadStreamed to temporary storage
  2. 02HashesMD5, SHA-1, SHA-256, SHA-512
  3. 03SignatureMagic number versus extension
  4. 04EntropyOverall and per chunk
  5. 05StringsURLs, IPs, emails, paths
  6. 06IndicatorsRule-based score, 0–100

Overview

A small full-stack application for practising digital forensics concepts. A file is streamed to temporary storage, run through an analysis pipeline, deleted, and the results are returned as a dashboard. It is an educational tool, not a production security product.

Challenge

Forensic concepts — magic numbers, entropy, string extraction — are easy to read about and hard to build intuition for. Seeing them computed on real files makes the difference.

Direction

Keep each analysis a small, separate service so it can be read and tested on its own, and frame every heuristic honestly: the risk score is a transparent rule-based indicator, never a malware verdict.

What was built

  • MD5, SHA-1, SHA-256 and SHA-512, computed in chunks so large files never load into memory
  • Signature detection against a table of common formats, with extension-mismatch flags
  • Overall and chunk-by-chunk Shannon entropy, charted
  • String extraction with detection of URLs, IP addresses, emails and paths
  • A rule-based heuristic score from 0 to 100, with each rule shown
  • Multi-file scan with duplicate grouping by SHA-256
  • Report export as JSON, CSV or a self-contained HTML file

Technology

  • React
  • Vite
  • Tailwind CSS
  • FastAPI
  • Python
  • pytest

Outcome

A working analysis pipeline and dashboard for studying file forensics, with uploads deleted as soon as each request completes.

Technical notes

  • Scope

    Built for education and forensic research practice. Its heuristic indicators are not malware detection and not forensic conclusions.

Start a project

Want something like this?

Tell me about the business and what the site needs to do.