Guides

Everything Tamperlens knows about reading a document's bytes, written out. The field guide is the reference; the rest are walkthroughs of one question each.

Which guide you need depends on two things: what the file is, and whether you are asking if it changed or if a machine made it.
Was it CHANGED after it was made? Was it MADE by a machine? A PDF or Office file Detect an edited PDF revisions · /ID pairs · Producer Detect an AI-generated PDF C2PA credential, or nothing An image Detect an edited image EXIF · encoder fingerprints Detect an AI-generated image a screenshot strips the credential Text you were sent No guide, and no signal. check the file it arrived in Detect AI-generated text classifiers guess; watermarks need a key Do you already hold the original? Then compare the two files directly: it beats every cell above, whatever the question was.

Every cell is a page below. The two columns are not degrees of the same thing: an edit leaves traces in the file's own history, and a generator either left a credential or left nothing at all.

Signal references

What the engine looks for, family by family, with the benign causes named alongside the malicious ones.

The nineteen families are grouped by which part of the file the signal is read from: not by how serious it is.
the field guide: nineteen families 5 Origin and history revisions, dates, /ID, Producer, XMP vs Info where it came from 7 Page content fonts, hybrid pages, redaction, injection what the page gives away 3 Signatures coverage, integrity, permissions what it actually covers 4 Numbers and structure CPF/CNPJ/boleto digits, running balance, glyphs when the page disagrees Nine more families run on images; those live in the image guides.

Counts are the ones the field guide itself publishes, family by family. Each group below is one page, and every family on it carries its benign causes and its severity logic.

Guides

One question each, answered end to end.

Looking for a tool rather than a guide?