Guides

Everything Tamperlens knows about reading a document's bytes, written out. The field guide is the reference; the rest are walkthroughs of one question each.

Signal references

What the engine looks for, family by family, with the benign causes named alongside the malicious ones.

  • Fraud signals field guide

    All eleven families that run on every PDF, what each detects, its benign causes, and how severity is decided.

  • PDF metadata forensics

    The Info dictionary, XMP, and what it means when a file's two records of its own history disagree.

Guides

One question each, answered end to end.

  • Detect an edited PDF

    Incremental updates, changed /ID pairs, editor fingerprints — how a PDF records its own edits.

  • Detect an edited image

    EXIF, encoder fingerprints, AI-generator metadata, and why an absence of metadata proves nothing.

  • Bank statement fraud signals

    What a forged statement looks like at the byte level, and what a legitimately re-saved one looks like.

  • PDF malware signals

    Embedded JavaScript, /OpenAction and launch actions — presence, reported honestly, not a verdict.

  • How comparison works

    Byte identity, revision ancestry and structural diff — what each one does and does not prove.

Looking for a tool rather than a guide?