{"repo":"michelcrypt4d4mus/pdfalyzer","free":true,"listed":false,"github":"https://github.com/michelcrypt4d4mus/pdfalyzer","clone":"git clone https://github.com/michelcrypt4d4mus/pdfalyzer.git","description":"Analyze PDFs with colors (and YARA)","language":"Python","stars":396,"topics":["malicious-pdf-files","malware-analysis","pdf","pdf-documents","pdf-format","pdf-parser","yara","yara-rules","yara-scanner"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"THE PDFALYZER A PDF analysis tool for visualizing the inner tree-like data structure[^1] of a PDF in spectacularly large and colorful diagrams as well as scanning the binary streams embedded in the PDF for hidden potentially malicious content. The Pdfalyzer makes heavy use of YARA (via The Yaralyzer) for matching/extracting byte patterns. Quick Start You can use pip but pipx is a cleaner way to install for normal users. Developers should probably use poetry . What It Do 1. Generate in depth visualizations of PDF tree structures [^1]. Shows every property of every PDF object at a glance. See the Example Output section below for details. 1. Scan for mad sus content with a bunch of PDF specific YARA rules. 1. Forcibly decode suspect bytes . The Yaralyzer does the heavy lifting. 1. Display detailed information about embedded fonts. With character maps. 1. Extract pages and/or text (including from embedded images) with the included command line tools. 1. Usable as a library for your own PDF related code. If you're looking for one of these things this may be the tool for you. What It Don't Do This tool is mostly for examining/working with a PDF's data and logical structure. As such it doesn't have much to offer as far as extracting text, rendering[^3], writing, etc. etc. If you suspect you are dealing with a malcious PDF you can safely run pdfalyze on it. Embedded javascript and /OpenAction nodes etc. will not be executed. If you want to actually look at the contents of a suspect P","default_branch":null,"files":null,"tree":[],"storefront":"/r/michelcrypt4d4mus","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/michelcrypt4d4mus/pdfalyzer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}