When to use this
Use this when a team member needs to audit why a file was allowed, rejected, or escalated.
How Verifence evaluates it
File Scanner is designed for untrusted PDF and Microsoft Office documents entering through forms, portals, support queues, or APIs. It combines antivirus and content-disarm signals with document-structure checks and analysis of URLs found inside the file.
Supported documents
PDF, Word, Excel, and PowerPoint files are supported in modern and legacy formats, up to 50 MB per file.
PDF normalization
PDFs are normalized before structural analysis so obfuscation layers are less likely to hide embedded files or links.
Office threat signals
Office documents are checked for macros and VBA behavior, DDE or external references, embedded OLE objects, XML external entities, and unsafe archive content.
Antivirus and CDR
Documents pass through the configured Cloudmersive antivirus and content-disarm pipeline for malware and active-content signals.
Embedded URL analysis
Links extracted from documents are checked for known bad reputation, shortened destinations, punycode, IP-based links, suspicious suffixes, new domains, and brand lookalikes.
Hashes and reporting
Successful scans are recorded with file metadata, hashes, verdicts, reasons, and engine details for later review.
How to do it
- 01 Open Scan Reports and locate the entry by time, filename, hash, team activity, or verdict.
- 02 Confirm the file metadata and SHA-256 hash match the document involved in the incident or support request.
- 03 Review the score, OK/Warn/Block rating, individual reason codes, extracted domains, and engine details.
- 04 Distinguish a hard threat detection from accumulated heuristic risk so the response matches the evidence.
- 05 Record the final disposition—released, quarantined, or rejected—in the client incident or case-management system.
How to act on the result
The scan found low risk. Continue with normal storage or processing while retaining the verdict for audit.
One or more elevated-risk signals need review. Quarantine the file instead of exposing it directly to users.
High-risk content was found. Known-bad URLs and antivirus detections force a block-level result.
The file was unsupported or could not be processed. Do not treat an error as a clean scan.
Implementation notes
- Each processed file costs 20 credits. Rejected or unprocessed files are refunded by the web scanning flow.
- The web tool accepts up to 20 files in one submission. The API accepts either one uploaded file or one public HTTP/HTTPS file URL, but not both.
- Remote-file scanning blocks private and reserved network destinations, limits redirects, uses a download timeout, and enforces the same 50 MB size ceiling.