Assemblyline PDFiD Service

Assemblyline service that extracts metadata and embedded objects from PDF files using Didier Stevens' PDFiD and PDFParser tools for security analysis.

  • Tools & Utilities
Assemblyline service that extracts metadata and embedded objects from PDF files using Didier Stevens' PDFiD and PDFParser tools for security analysis.

Platform availability

Available on 1 of 9 platforms

  • Unraid (not listed)
  • TrueNAS (not listed)
  • Umbrel (not listed)
  • ZimaOS (not listed)
  • Proxmox
  • Helm (not listed)
  • Mac (not listed)
  • Windows (not listed)
  • Linux (not listed)

Health score?A 0-100 score computed nightly from four factors: maintained (40%: recent commits and steady activity), popular (25%: GitHub stars, log scale), easy to install (20%: platforms, install notes, setup guides, Docker image) and light to run (15%: minimum RAM, ARM support). When the source code has been checked, a fifth factor, security check (20%: automated scan for committed secrets, unsafe desktop-app settings, known-vulnerable dependencies and project hygiene; any serious finding caps it at 20), is added. Factors without data are left out and the rest are rescaled.

35/100 Low

Maintained
58last commit 176 days ago
Popular
176 GitHub stars
Easy to install
100 install platforms, Docker image
Light to run
No data

Based on 3 of 4 factors.

GitHub stars
6
Open issues
0
Last commit
2026-04-17
Latest release
v4.7.0.stable4
Activity
stale

Checked 12 days ago - source: GitHub (CybercentreCanada/assemblyline-service-pdfid)

Resources & Compatibility

ARM (e.g. Raspberry Pi) is not supported.

Checked 12 days ago - source: Docker Hub image tags and published docs

First-install notes

  • Service Configuration Configure this service through Assemblyline's service parameters and service variables. In a Docker Compose appliance deployment, certain services require special configuration to run efficiently. Refer to the Assemblyline 4 service management documentation for detailed setup instructions. source

Fetched today - each note links to its source

Alternatives

No alternatives collected yet.

Common questions

When does the PDFId service run PDFParser on a sample?

PDFParser runs only if the sample is in deep scan mode, or if selected PDFId plugins flag suspicious elements.

Does MAX_PDF_SIZE still limit processing during a deep scan?

No, the maximum PDF size setting is ignored during deep scan.

Can users add their own PDFId heuristics plugins?

Yes, PDFId plugins are Python scripts that can be added by users. A plugin class must define onlyValidPDF, name, and an __init__ method that receives the PDFId object.

Does the service extract suspicious PDF objects as files?

PDFParser can extract entire objects as extracted files when PDFId plugins flag them. JBIG2Decode objects are only extracted in deep scan mode.

Is the PDFId service available as a container image?

Yes, a container image is published for the PDFId service.

Answers sourced from github.com, hub.docker.com

Community

Collected 6 days ago - public community threads