PDF Threat Scanner
Scan PDF files for suspicious patterns including JavaScript actions, Launch commands, URI redirects, embedded files, and auto-execute open actions. Over 40 patterns detected across 12 categories with severity ratings. Paste PDF text or upload a file - all processing is local and private.
Scan PDF text content for suspicious patterns including JavaScript actions, URI redirects, Launch commands, embedded files, and open actions. Paste raw PDF text or upload a .pdf file. All processing happens locally in your browser.
Paste PDF text content or upload a .pdf file above, then click Scan for Threats. The scanner analyzes the raw PDF text for suspicious patterns including JavaScript actions, URI redirects, Launch commands, embedded files, and automatic open actions. All processing is local - your files never leave your device.
Why Use Our PDF Threat Scanner?
Comprehensive Threat Detection
Detect over 40 suspicious PDF patterns across categories including JavaScript execution, URI actions, embedded file streams, Launch actions, form field manipulation, metadata anomalies, open actions, and cross-document collaboration. Each detection includes severity rating, category, and detailed description of the threat.
Multi-Layer Pattern Analysis
The scanner analyzes PDF content at multiple levels: raw PDF operations like /OpenAction and /AA actions, JavaScript indicators like /JS and /JavaScript entries, file attachment patterns like /EmbeddedFile and /Filespec, URI handling schemes like /URI and /Launch, and metadata anomalies like missing /Type entries or invalid page references.
Severity-Rated Findings
Each detected pattern is assigned a severity level - Critical (immediate code execution), High (likely malicious), Medium (suspicious), or Low (informational). Results are grouped by category and sorted by severity so you can focus on the most dangerous findings first.
Multiple Input Methods & Privacy
Paste raw PDF text content directly, upload a PDF file for analysis, or load built-in example PDF patterns. All processing is local - your PDF content never leaves your browser. No uploads to servers, no data collection, no signup required.
Common Use Cases for PDF Threat Scanner
Malware Analysis & Phishing Investigation
Security analysts use the threat scanner to quickly triage suspicious PDF files received via email or downloaded from untrusted sources. A single scan reveals embedded JavaScript, auto-execute actions, URI redirections, and hidden form fields - all common vectors in PDF-based phishing campaigns and malware delivery.
Incident Response & Forensics
During incident response, investigators scan PDF files found on compromised systems to identify how attackers delivered payloads. The scanner reveals /Launch actions that execute shell commands, /URI actions that redirect to exploit pages, and /EmbeddedFile entries containing malicious binaries.
Email Security Gateway Validation
IT security teams can validate PDF attachments that pass through email security gateways. By scanning PDFs for obfuscated URI strings, encoded JavaScript, and suspicious open actions, analysts can identify threats that evaded automated email filtering through PDF-based evasion techniques.
PDF Development Security Testing
Developers building PDF processing applications use the scanner to test their PDF parsers against known malicious patterns. Understanding how /JS actions, /EmbeddedFiles, and /OpenAction entries manifest in PDF text helps build more robust PDF validation and sanitization code.
Security Awareness & Training
Security trainers use the threat scanner to demonstrate how malicious PDFs work in a safe, controlled environment. The visual breakdown of suspicious patterns helps trainees understand why they should never open PDF attachments from unknown senders and how attackers weaponize seemingly innocent PDF files.
Vulnerability Research & Threat Intelligence
Threat intelligence researchers analyze PDF samples from malware repositories to categorize attack techniques. The scanner standardizes the analysis process, making it easy to catalog PDF-based TTPs, track evolving obfuscation methods, and generate consistent reports for threat sharing platforms.
Understanding PDF Threat Patterns
What are PDF Threat Patterns?
PDF threat patterns are specific structures, actions, and entries within a PDF file that indicate malicious intent or security risk. Unlike plain text documents, PDF files can contain executable JavaScript, auto-execute actions triggered when the document opens, embedded files that drop binaries onto the system, and URI actions that redirect users to malicious websites. Attackers exploit these PDF capabilities to deliver malware, phish credentials, and execute code on victim machines. The PDF Suspicious Pattern Scanner analyzes the raw text representation of a PDF file to identify these dangerous patterns before the file is opened in a PDF reader.
How the Threat Scanner Works
- Text Extraction - The scanner takes raw PDF text content as input, either pasted directly or extracted from an uploaded .pdf file. The PDF is read as text to expose the human-readable PDF operators, dictionaries, and stream declarations that form the document structure.
- Pattern Matching - The text is scanned against a comprehensive database of regex patterns organized into categories: JavaScript Actions (/JS, /JavaScript), URI Actions (/URI, /Launch), Embedded Files (/EmbeddedFile, /Filespec), Open Actions (/OpenAction, /AA), Form Field Actions (/SubmitForm, /ImportData), Document Manipulation (/OpenInPlace), Cross-Document (/GoToR), Annotations (/RichMedia), and Metadata Anomalies.
- Severity Scoring - Each detected pattern is assigned a severity level based on the potential impact: Critical patterns allow immediate code execution (/Launch, /JavaScript with commands), High patterns involve URI redirects or embedded files, Medium patterns include suspicious open actions and form manipulation, and Low patterns are informational (JavaScript version checks, metadata anomalies).
- Result Presentation - Findings are grouped by category, sorted by severity, and displayed with the exact matched text context. A summary dashboard shows total findings, top severity counts, and the overall risk assessment.
Common PDF Attack Vectors
- Auto-Execute JavaScript: /OpenAction combined with /JS entries that execute JavaScript when the PDF is opened. Attackers use this to launch exploits, download malware, or redirect to phishing pages without any user interaction.
- Command Execution via /Launch: The /Launch action allows a PDF to execute external applications. Attackers pair this with malicious parameters to run shell commands, launch PowerShell scripts, or execute embedded binaries. Modern PDF readers have restricted this, but legacy configurations remain vulnerable.
- URI Redirection & Phishing: /URI actions embedded in PDFs can redirect the reader to malicious websites. Attackers obfuscate URLs using encoding schemes to bypass text-based filtering. Combined with /OpenAction, the redirect happens automatically when the document opens.
- Embedded File Payloads: /EmbeddedFile streams can contain malware binaries, VBA macros, or malicious scripts. The /Filespec entry provides the filename, which attackers often disguise as legitimate documents (.pdf, .docx) while the actual content is executable.
- Form Field Data Theft: /SubmitForm and /ImportData actions can exfiltrate form data to remote servers without user awareness. Attackers create invisible form fields that capture user information and submit it via HTTP POST.
Privacy & Security
This tool runs entirely in your browser using client-side JavaScript. Your PDF content, uploaded files, and scan results are never uploaded to any server, stored in any database, or transmitted over the network. All pattern matching, severity scoring, and category grouping executes locally on your device. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it completely safe for scanning confidential PDFs, sensitive malware samples, or proprietary documents.
Frequently Asked Questions About PDF Threat Scanner
The scanner detects over 40 suspicious PDF patterns including JavaScript actions (/JS, /JavaScript), auto-execute open actions (/OpenAction), additional actions (/AA), URI redirects (/URI), embedded files (/EmbeddedFile, /Filespec), Launch actions that execute applications (/Launch), form data submission (/SubmitForm), cross-document references (/GoToR, /OpenInPlace), rich media annotations (/RichMedia), firmware entries (/Firmware), and metadata anomalies like missing /Type or /Pages entries.
Not at all. Simply paste PDF text content or upload a PDF file, and the scanner automatically identifies all detected threats with plain-English descriptions, severity ratings (Critical, High, Medium, Low), and category groupings. Each finding explains why the pattern is suspicious and what attackers might use it for. The results dashboard gives you an instant risk overview.
Critical severity is assigned to patterns that enable immediate code execution - /Launch actions that can run shell commands, /JavaScript entries paired with auto-execute triggers, and combined action sequences that execute without user interaction. High severity covers URI redirects, embedded file attachments, and submit-form actions. Medium includes suspicious open actions, cross-document references, and additional actions. Low covers informational items like JavaScript version checks and common metadata.
The scanner works on the raw text representation of PDF files, which reveals PDF operators, stream declarations, and action entries even when the actual content is compressed or encoded in streams. While it excels at detecting structural PDF threats (actions, entries, and references), heavily obfuscated JavaScript or encoded payloads within compressed streams may require stream decompression. The scanner flags all entries that reference executable content for further investigation.
A /Launch action tells the PDF reader to execute an external application. When paired with malicious parameters, it can run shell commands, launch PowerShell with encoded scripts, or execute embedded binaries. Even though modern PDF readers prompt for confirmation, many users click through these warnings. Combined with social engineering messages displayed in the PDF, /Launch actions remain a common attack vector.
Absolutely. The PDF Threat Scanner runs entirely in your browser using client-side JavaScript. Your PDF content, uploaded files, and scan results are never uploaded to any server, stored in any database, or transmitted over the network. All pattern matching and analysis executes locally on your device with no API calls, analytics tracking, cookies, or data collection of any kind.
Yes. The scanner provides a copy report feature that generates a plain text summary of all findings including file size, total findings, severity breakdown, and every detected pattern with its exact matched text, severity, category, and description. You can copy this report to your clipboard for documentation, sharing with your security team, or attaching to incident reports.
Yes - 100% free with no signup, no account, and no usage limits. Scan as many PDFs as you need, as many times as you want. There are no premium tiers, hidden charges, or rate limits. The tool runs entirely in your browser - your files never leave your device.