Upload a signed PDF to audit its signatures, revisions and layer integrity. The verdict, signer identities, PAdES tiers and any tamper flags appear here.
Choose a PDF to begin.
PDF Signature Forensics & Document Layer Integrity Analyzer
A byte-level forensic engine for digitally signed PDFs. It parses the raw file buffer — not a viewer's rendered model — to verify what each signature actually covers, decode the CMS/PKCS#7 cryptography, walk the incremental-update revision chain, and detect shadow attacks and in-place visual overlays. Everything runs in a Web Worker in your browser; the file never leaves your device and no CA, OCSP or timestamp server is ever contacted.
What it verifies
- ByteRange integrity: the
[o1 l1 o2 l2]window is checked against the file — it must start at byte 0 and leave a gap only for/Contents. Secondary ByteRange/Contents injections and trailing unsigned data are flagged. - CMS / PKCS#7: the DER SignerInfo is decoded and the signature math verified with WebCrypto — RSASSA-PKCS1-v1_5, RSA-PSS and ECDSA over SHA-256/384/512 — against the exact signed bytes.
- Certificates & PAdES tier: the certificate chain, key usage and validity windows are surfaced, and the PAdES profile (B-B / B-T / B-LT / B-LTA) is classified from embedded timestamps and the DSS.
- Incremental updates: every
%%EOFrevision is diffed to separate permitted additions (a later signature, a DSS) from suspicious mutations that redefine signed objects. - Shadow attacks: Hide, Replace and Hide-and-Replace vectors — a swapped Catalog or Pages tree, mutated AcroForm/XFA, redefined fonts, or an opaque content-stream overlay drawn over signed content.
On trust anchors and revocation
Because this tool is strictly local, it does not validate certificates against AATL / eIDAS trust lists or perform live OCSP/CRL revocation checks — both would require network calls and shipping large trust stores. Embedded revocation material (DSS/VRI) and timestamp tokens are decoded and shown, but reported as not validated. For legal non-repudiation sign-off, confirm trust-anchor and revocation status in a validator with network access.
