NS Guard inspects files by signature, structure, and behavior pattern, not by trusting a filename. Every result shows its evidence.
Scan a file
Every file is identified by its actual byte structure, so a renamed executable cannot pass as an image or document.
PE headers, sections, imports, and entropy are parsed directly. Archives are extracted and each file inside is analyzed on its own.
Credential and session-theft heuristics require multiple corroborating signals before flagging anything, not a single keyword match.
Upload a file or archive for analysis.
Drag and drop a file here, or click to browse
Maximum file size: 100 MB
Previously completed scans.
Look up a SHA-256 hash against this platform's own scan history.
This looks up the hash only within this NS Guard deployment's own scan history.
Scan and privacy preferences for this deployment.
What NS Guard analyzes, and its honest limitations.