PQ PDF — PDF Scanner, 44 Engines
15 static heuristic analyzers — PDF token obfuscation, XFA FormCalc auto-execute, action dependency graph (cycle detection, sleeper nodes), OCG layer cloaking (screen/print divergence), Unicode & invisible text (RLO U+202E, homograph domains), trailer chain forensics (Shadow Attack, /Root swap), codec exploit validation (CCITTFax OOB, JBIG2Globals CVE-2009-0658), physical entropy topology, image steganography (LSB chi-square, JPEG EXIF anomalies), font CharString emulator (Type 1, seac OOB), PDF/A compliance fraud, YARA (24 rules including CVE-2024-41869 + CVE-2024-45112), ClamAV, PeePDF, campaign attribution via TLSH fuzzy-hash.
6 dynamic sandboxes — Ghostscript, MuPDF, Poppler, LibreOffice Draw, Chromium PDFium, and pdf.js/Node, each with strace syscall tracing. 3 ML classifiers — IsolationForest, RandomForest, LightGBM on a 38-feature vector with SHAP explainability and a 6-parser differential engine. 6.4M+ local threat indicators (URLhaus, MalwareBazaar, ThreatFox — zero external API calls). MITRE ATT&CK mapping on every finding. 9 sanitization modes. AI forensic reports via local Qwen 2.5 1.5B — no cloud. Zero retention: cleanup runs during readfile(), not after download.