Toilet Duck

Everything Stays Local

Document malware, and sanitising it without uploading anything.

Slides

Presents in the browser — arrow keys, space or click to advance, f for full screen.

Present → Everything Stays Local 25 slides · the five families of document-borne execution, why the usual defences fit badly, and the demonstrations that show it against real files rather than describing it

Or take the PDF, or the PowerPoint.

Code

Download → applications and scripts the tool itself, entries.py and the scripts that build and test it, the Python sanitiser it was ported from, and Didier Stevens’ pdfid.py and oledump.py bundled with hashes and provenance

Paper

Read → companion paper 9 pages · the same material argued rather than asserted — the full PDF action table, where the tool deliberately disagrees with the sanitiser it was ported from, and the implementation mistakes with enough context to be useful

Tools used in the demonstrations

Linked rather than bundled. These are other people’s tools, and you want the current version from the author, not a copy frozen inside a talk.


What the talk covers

The tool

Toilet Duck Web is a single index.html. It opens from disk, has no dependencies, and makes no network requests — the files you scan never leave the machine. toiletduck.cleaning