- examples/inputs/bytes-pattern-samples/sample.elf
- examples/inputs/bytes-pattern-samples/sample.exe
- examples/inputs/bytes-pattern-samples/sample.gif
- examples/inputs/bytes-pattern-samples/sample.jpg
- examples/inputs/bytes-pattern-samples/sample.pdf
- examples/inputs/bytes-pattern-samples/sample.png
- examples/inputs/bytes-pattern-samples/sample.zip
# Bytes Pattern Example Profile
# Demonstrates detection of file format magic bytes and binary patterns
decode = []
max-file-size = 10485760 # 10 MiB
tag = "bytes-pattern"
# Common file format magic bytes
[[patterns]]
name = "PDF Header"
pattern = "25:50:44:46"
type = "bytes"
[[patterns]]
name = "PNG Header"
pattern = "89:50:4E:47:0D:0A:1A:0A"
type = "bytes"
[[patterns]]
name = "JPEG Header"
pattern = "FF:D8:FF"
type = "bytes"
[[patterns]]
name = "GIF Header"
pattern = "47:49:46:38"
type = "bytes"
[[patterns]]
name = "ZIP Header"
pattern = "50:4B:03:04"
type = "bytes"
[[patterns]]
name = "RAR Header"
pattern = "52:61:72:21:1A:07"
type = "bytes"
[[patterns]]
name = "7z Header"
pattern = "37:7A:BC:AF:27:1C"
type = "bytes"
[[patterns]]
name = "ELF Header"
pattern = "7F:45:4C:46"
type = "bytes"
[[patterns]]
name = "PE MZ Header"
pattern = "4D:5A"
type = "bytes"
[[patterns]]
name = "Office 2007+ (OOXML)"
pattern = "50:4B:03:04:14:00:06:00"
type = "bytes"
# Suspicious binary patterns
[[patterns]]
name = "Null Sled"
pattern = "00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00"
type = "bytes"
[[patterns]]
name = "NOP Sled (x86)"
pattern = "90:90:90:90:90:90:90:90"
type = "bytes"
| total_files | 7 |
| critical_count | 0 |
| high_count | 0 |
| medium_count | 0 |
| low_count | 0 |
| minimal_count | 7 |
| must_investigate_count | 0 |
| all_scores | None |
| generated_at | 2025-12-03T09:19:43.962770608+00:00 |
| characteristics_score | file_type | file_type_score | must_investigate | path | pattern_count_score | pattern_matches | pattern_severity_score | reasons | risk_level | score | sha256 |
| 0 | Executable | 15 | False | /sample.exe | 5 | 1 | 0 | ["1 suspicious patterns detected"] | Minimal | 20 | d16ee5307c6e0496c864459af449e0c656e4d8e5bdfee83af451fb2dd7ff64a4 |
| 0 | Archive | 10 | False | /sample.zip | 5 | 1 | 0 | ["1 suspicious patterns detected"] | Minimal | 15 | 56a388646e23dc611a253164567dcbea2ceb47e2ce09b7f8e68a19c7f6d9f5e2 |
| 0 | Document | 5 | False | /sample.pdf | 5 | 1 | 0 | ["1 suspicious patterns detected"] | Minimal | 10 | d0958bf2d40e26b2328c44773a9046034fb66ccdbabdb79d2d750bbeffdcfcdf |
| 0 | Other | 0 | False | /sample.jpg | 5 | 1 | 0 | ["1 suspicious patterns detected"] | Minimal | 5 | b6ecc495cbd46cc09da3f32ebdb94a81712e1986bde12a8706f36fd6dcc8a098 |
| 0 | Other | 0 | False | /sample.png | 5 | 1 | 0 | ["1 suspicious patterns detected"] | Minimal | 5 | c42551b23e7594bfd846066c9c898cb611c17146ff79dfa892afeded01d3b735 |
| 0 | Other | 0 | False | /sample.gif | 5 | 1 | 0 | ["1 suspicious patterns detected"] | Minimal | 5 | 5bb6b67a22ce0b967a1cf687f3d00bb8b433fcc39d298cde9a67597f258a4368 |
| 0 | Other | 0 | False | /sample.elf | 5 | 1 | 0 | ["1 suspicious patterns detected"] | Minimal | 5 | 231c966fcf4e051785578a1cc41fd52e0ba3d56b72ebcdb2f68600c95fa927a5 |
Empty CSV
| path | file_name | sha256 | file_created | file_modified | file_accessed | mime_types_from_file_extension | is_symbolic_link | is_extracted_file | is_decoded_file | is_deobfuscated_file | tag |
| /sample.zip | sample.zip | 56a388646e23dc611a253164567dcbea2ceb47e2ce09b7f8e68a19c7f6d9f5e2 | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | ["application/zip"] | 0 | 0 | 0 | 0 | |
| /sample.jpg | sample.jpg | b6ecc495cbd46cc09da3f32ebdb94a81712e1986bde12a8706f36fd6dcc8a098 | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | ["image/jpeg"] | 0 | 0 | 0 | 0 | |
| /sample.png | sample.png | c42551b23e7594bfd846066c9c898cb611c17146ff79dfa892afeded01d3b735 | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | ["image/png"] | 0 | 0 | 0 | 0 | |
| /sample.gif | sample.gif | 5bb6b67a22ce0b967a1cf687f3d00bb8b433fcc39d298cde9a67597f258a4368 | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | ["image/gif"] | 0 | 0 | 0 | 0 | |
| /sample.exe | sample.exe | d16ee5307c6e0496c864459af449e0c656e4d8e5bdfee83af451fb2dd7ff64a4 | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | ["application/x-dosexec","application/x-dosexec","application/x-ms-ne-executable","application/vnd.microsoft.portable-executable"] | 0 | 0 | 0 | 0 | |
| /sample.pdf | sample.pdf | d0958bf2d40e26b2328c44773a9046034fb66ccdbabdb79d2d750bbeffdcfcdf | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | ["application/pdf"] | 0 | 0 | 0 | 0 | |
| /sample.elf | sample.elf | 231c966fcf4e051785578a1cc41fd52e0ba3d56b72ebcdb2f68600c95fa927a5 | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | 2025-12-03T08:56:20.495889189Z | ["application/x-executable"] | 0 | 0 | 0 | 0 | |
| id | sha256 | pattern_name | match_type | match | location | length |
| 1 | 56a388646e23dc611a253164567dcbea2ceb47e2ce09b7f8e68a19c7f6d9f5e2 | ZIP Header | bytes | PK | 0 | 4 |
| 2 | b6ecc495cbd46cc09da3f32ebdb94a81712e1986bde12a8706f36fd6dcc8a098 | JPEG Header | bytes | ��� | 0 | 3 |
| 3 | c42551b23e7594bfd846066c9c898cb611c17146ff79dfa892afeded01d3b735 | PNG Header | bytes | �PNG | 0 | 8 |
| 4 | 5bb6b67a22ce0b967a1cf687f3d00bb8b433fcc39d298cde9a67597f258a4368 | GIF Header | bytes | GIF8 | 0 | 4 |
| 5 | d16ee5307c6e0496c864459af449e0c656e4d8e5bdfee83af451fb2dd7ff64a4 | PE MZ Header | bytes | MZ | 0 | 2 |
| 6 | d0958bf2d40e26b2328c44773a9046034fb66ccdbabdb79d2d750bbeffdcfcdf | PDF Header | bytes | %PDF | 0 | 4 |
| 7 | 231c966fcf4e051785578a1cc41fd52e0ba3d56b72ebcdb2f68600c95fa927a5 | ELF Header | bytes | ELF | 0 | 4 |
Empty CSV
| sha256 | sha1 | md5 | file_size | mime_type_for_content | shannon_entropy |
| d16ee5307c6e0496c864459af449e0c656e4d8e5bdfee83af451fb2dd7ff64a4 | fafd69e17d88a9ae35109fa3779319c4608aab70 | a96dd69ec3fb1cdc5a3e3f294dae43e9 | 44 | application/octet-stream | 4.35327174447691 |
| 56a388646e23dc611a253164567dcbea2ceb47e2ce09b7f8e68a19c7f6d9f5e2 | 03807180f234ac4604b248483d674d3a9569a29b | 1bbc604980f4148810b652723090d7f4 | 42 | application/octet-stream | 4.66935247095495 |
| b6ecc495cbd46cc09da3f32ebdb94a81712e1986bde12a8706f36fd6dcc8a098 | d37f332b2d81aa9c45807f10d17c0994d58f6533 | 0c908b4e1f9603e2f5923bb245178ced | 34 | image/jpeg | 4.55805107654446 |
| c42551b23e7594bfd846066c9c898cb611c17146ff79dfa892afeded01d3b735 | cf896d9a3db62a00d319b059066913ad8341e8c4 | 014197e91280729f9d45a58b8e154196 | 44 | image/png | 4.57035399411994 |
| 5bb6b67a22ce0b967a1cf687f3d00bb8b433fcc39d298cde9a67597f258a4368 | c764e4297f27a68e0c41836821094fc747c6d1a7 | 49752eea6c6ad2a78c6fb6aacda67556 | 48 | image/gif | 4.17609473185782 |
| d0958bf2d40e26b2328c44773a9046034fb66ccdbabdb79d2d750bbeffdcfcdf | c32c560d7176d306a6064aa8d08eef2a1f3c3ea1 | 0c7faf0fa95a6884de094d634186f46d | 73 | application/pdf | 4.30826328831621 |
| 231c966fcf4e051785578a1cc41fd52e0ba3d56b72ebcdb2f68600c95fa927a5 | 2ff43a51e0a70b5b1653438b1481c018944c1a5b | f1dab7b7b2f093a3283f36b4e8b9c598 | 41 | application/x-executable | 4.25951419952897 |