FileScan.Core 0.1.1

There is a newer version of this package available.
See the version list below for details.
dotnet add package FileScan.Core --version 0.1.1
                    
NuGet\Install-Package FileScan.Core -Version 0.1.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="FileScan.Core" Version="0.1.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="FileScan.Core" Version="0.1.1" />
                    
Directory.Packages.props
<PackageReference Include="FileScan.Core" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add FileScan.Core --version 0.1.1
                    
#r "nuget: FileScan.Core, 0.1.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package FileScan.Core@0.1.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=FileScan.Core&version=0.1.1
                    
Install as a Cake Addin
#tool nuget:?package=FileScan.Core&version=0.1.1
                    
Install as a Cake Tool

FileScan.Core

Upload file validation for .NET — in-process, no API call, no antivirus daemon required.

Most upload pipelines trust the file extension. Malicious uploads — PDFs with auto-executing JavaScript, Office documents with DDE/macros, CSV formula injection, polyglot images — pass an extension check, and pass signature-based antivirus when the payload is new. FileScan.Core catches this class of attack at the application layer, before the file reaches storage.

Documentação em português: veja o repositório no GitHub.

Usage

using FileScan.Scanning;

var scanner = new FileScanService(new FileScannerOptions
{
    AllowedExtensions = ["pdf", "docx", "xlsx", "csv", "jpg", "png"],
    // MaxFileSizeBytes / MaxDecompressedBytesPerStream / OnActiveContent — per-instance options
});

ScanResponse result = await scanner.ScanAsync(fileName, bytes);
if (result.Verdict != ScanVerdict.Clean)
    Reject(result.Reason); // Rejected: reason says exactly what was found

Options are per instance (no global state): two consumers in the same process can use different limits.

What it checks

  1. Structural (cheap, synchronous): size, extension allowlist, and real content type via magic bytes (Mime-Detective) — rejects dangerous binaries (a disguised .exe) and files whose content doesn't match the declared extension.
  2. Active content (multi-format heuristics):
    • PDF: JavaScript (/JavaScript, /JS), /Launch, recursive inspection of embedded attachments; streams are always decompressed before being judged (compressed bytes are never scanned raw — no random-data false positives), and hex-encoded names (/J#53 ≡ /JS) are normalized so they can't evade detection.
    • Office OOXML (docx/xlsx): DDE, VBA macros, formula injection, embedded OLE objects.
    • CSV: formula/command injection per OWASP.
    • Images (jpg/png/gif): embedded <script>/<?php.
    • Legacy/HTML (doc/xls): scripts, DDE, macro markers.
  3. Antivirus (optional, pluggable): implement IVirusScanner to add an engine. The FileScan API plugs ClamAV in this way; without one, the structural + active-content layers run on their own.

Policy is configurable (OnActiveContent): Reject (default), Flag (pass with Warnings), or Ignore.

Scope

FileScan.Core does heuristic detection of malicious/active content. It is not a certified CDR product and does not replace a full antivirus — use it as a defense-in-depth layer and validate in your own context. Encrypted/obfuscated payloads and zero-day threats may evade it. See the repository's SECURITY.md for known evasions/limitations and caller responsibilities when serving uploaded files.

License

MIT — see the repository's LICENSE.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.2.0 116 9/1/2026
0.1.1 103 8/31/2026