Show HN: FileGuard – Detect files with fake extensions in real-time

  • Posted 6 hours ago by anasrm01
  • 1 points
https://github.com/AnasRm01/file-validator
Creator here. Built this after seeing ransomware evade AV by renaming .exe to .pdf during an IR investigation.

Uses magic number validation - checks if invoice.pdf actually starts with %PDF. Lightweight (inotify-based), quarantines suspicious files, SIEM-ready logs.

One-line install for Linux/Windows. Would love feedback!

Tech stack: Python, inotify (Linux), watchdog (Windows), YAML config

2 comments

    Loading..
    Loading..