# CorbelPurge > Strict Rust document sanitizer & threat neutralizer for PDF, EPUB, Markdown, and DOCX. **Author:** Jeremy Anderson — [dcos.net](https://dcos.net) — [info@dcos.net](mailto:info@dcos.net) **Repository:** [https://git.dcos.net/dcosnet/corbel](https://git.dcos.net/dcosnet/corbel) **License:** GPL-3.0-or-later ![Corbel-Purge-ss](./corbel-purge-ss.png) ## Overview CorbelPurge is a strict, local-only document security scanner. It parses documents into a unified intermediate representation, runs detectors that are backed by verifiable properties of the bytes on disk, and produces cleansed derivatives with all executable content stripped. Malicious payloads are carved into quarantine tarballs with full forensic reports. The scanner is built around a single design invariant: **every detector must be backed by a verifiable property, either of the document itself or of an external authority.** No thresholds, no per-file or per-domain exceptions, no statistical "suspicious" tier. ## What it does Given a file path, `Pipeline::run()` in `src/core/pipeline.rs`: 1. **Detects format** via `DocumentFormat::from_path()` (extension-based: `.pdf`, `.epub`, `.md`/`.markdown`, `.docx`). 2. **Parses** via `parsers::Dispatcher` into a `Document` containing `TextNode` (static text with semantic context) and `ExecutableVector` (active content like JS streams, embedded files, script tags, VBA macros) items. 3. **Scans** with a two-pass engine: - `heuristics::inspect_vector()` classifies every executable vector against the two-category detector model: Category 1 (verifiable executable intent — file signatures, shellcode prologues, executable URI schemes) and Category 2 (verifiable impersonation — exact-host homographs, credential URLs, mixed-script hosts). - `context_filter::evaluate()` checks text nodes for structural signatures (`/JavaScript`, `_.{json,md}`. The clean path provides an audit trail; the malicious path adds a quarantine tarball and carved payloads. 5. **Quarantines** (when malicious findings exist) — `quarantine::handle()` carves payloads into `quarantine__.tar.gz` with `original.`, `report.json`, `report.md`, and one `.bin` per payload (plus paired `.hex` and `.info` files). 6. **Cleanses** (when recommended) — produces a sanitized derivative: - **Markdown mode** (default): `cleanse::sanitizer::sanitize()` emits a safe Markdown file. Text nodes at malicious locations are stripped; hyperlinks lose their destinations. - **PreserveFormat mode** (`--preserve-format`): `cleanse::repackage::repackage()` rebuilds the original format with malicious entries removed. EPUB entries are stripped from the ZIP, DOCX macros/embeddings/external-links are removed, PDF objects are deleted via lopdf. 7. **Clean-output** (when scan is clean and `emit_clean_output` is on, the default) — copies the source file to `corbel_clean/clean__.` so the scanner acts as a pipeline stage. Use `--move-clean` for queue-draining semantics. Supported formats: **PDF**, **EPUB**, **Markdown**, **DOCX**. ## Detection model Two categories. Nothing else fires. ### Category 1 — Verifiable executable intent The vector contains a structure whose only purpose is to execute code or spawn a process. Presence is the threat. | Detector | Triggers on | |---|---| | Active script in PDF | `/JavaScript` or `/JS` action stream | | Program launch in PDF | `/Launch` action with `/F`, `/Win`, `/Mac`, `/Unix` | | External program exec in EPUB | `