Document-based malware remains a dominant initial access vector in modern cyber intrusions due to the
widespread use and structural complexity of Portable Document Format (PDF) and Microsoft Office files. Traditional
detection-based defenses, including signature matching and machine learning classifiers, struggle against obfuscation, zero
day exploits, and format-level evasions. Content Disarm and Reconstruction (CDR) addresses this challenge by adopting a
zero-trust document handling model that eliminates entire attack surfaces rather than attempting malware classification. This
paper presents the design, implementation, and evaluation of a lightweight, format-aware CDR system capable of sanitizing
PDF and Microsoft Office OOXML documents through deterministic structural disarmament and secure reconstruction. The
proposed system performs static byte-level analysis, extracts forensic Indicators of Compromise (IOCs), removes active and
executable document components, and reconstructs clean artifacts without rendering or executing any embedded content. A
risk-scoring mechanism based on residual structural indicators and IOC density enables conservative delivery decisions while
maintaining forensic auditability. The system is evaluated using a curated dataset of benign and real-world malicious PDF
and Microsoft Office (DOCX) documents obtained from Malware Bazaar and public academic sources. Experimental results
demonstrate that for PDF files, the system achieves an average attack surface reduction of approximately 34.7% (with a mean
Sanitization Success Rate of 30.8% across files with threats) and a combined threat neutralization rate of 65% for low and
medium risk documents, while producing stable and predictable sanitized outputs. For DOCX files, the system successfully
extracts forensic indicators but leaves obfuscated macro streams intact, highlighting format-specific limitations and directing
future work.
[1] T. Gupta and R. Finn, “Adobe Brings Conversational AI to Trillions of PDFs with the New AI Assistant in Reader and Acrobat.”
[Online]. Available: www.adobe.com.
[2] A. E. Abdallah, Y. Al Sawafteh, E. E. Abdalah, and S. Al-Saleh, “Survey of Malicious PDF Detection Systems: Methods,
Challenges, and Advances,” in Procedia Computer Science, Elsevier B.V., 2025, pp. 1086–1091. doi: 10.1016/j.procs.2025.03.142.
[3] S. S. P, “PDFInspect: A Unified Feature Extraction Framework for Malicious Document Detection,” Jan. 2026, [Online]. Available:
http://arxiv.org/abs/2601.12866
[4] Mrs. P. Patil, “Detection of Malware in PDF and Office Documents using Ensemble learning,” IJARCCE, vol. 12, no. 11, Nov. 2023,
doi: 10.17148/ijarcce.2023.121108.
[5] T. M. Mohammed, L. Nataraj, S. Chikkagoudar, S. Chandrasekaran, and B. S. Manjunath, “HAPSSA: Holistic Approach to PDF
Malware Detection Using Signal and Statistical Analysis,” Nov. 2021, [Online]. Available: http://arxiv.org/abs/2111.04703
[6] S. Y. Yerima, A. Bashar, and G. Latif, “Malicious PDF detection Based on Machine Learning with Enhanced Feature Set,” 2022.
[7] D. Li, Q. Li, Y. Ye, and S. Xu, “Arms Race in Adversarial Malware Detection: A Survey,” Aug. 2021, doi: 10.1145/3484491.
[8] T. Olzak, “Content Disarm and Reconstruction (CDR),” Security Intelligence Report, 2025.
[9] R. Dubin, “Content Disarm and Reconstruction of RTF Files a Zero File Trust Methodology,” IEEE Transactions on Information
Forensics and Security, vol. 18, pp. 1461–1472, 2023, doi: 10.1109/TIFS.2023.3241480.
[10] R. Dubin, “Content Disarm and Reconstruction of PDF Files,” IEEE Access, vol. 11, pp. 38399–38416, 2023, doi:
10.1109/ACCESS.2023.3267717.
[11] R. Dubin, “Content Disarm and Reconstruction of Microsoft Office OLE Files Highlights Content Disarm and Reconstruction of
Microsoft Office OLE Files.” [Online]. Available: https://ssrn.com/abstract=4590246
[12] S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” Gaithersburg, MD, Aug. 2020. doi:
10.6028/NIST.SP.800-207.
[13] Ifigeneia. Lella, Marianthi. Theocharidou, Eleni. Tsekmezoglou, and Apostolos. Malatras, ENISA threat landscape 2021: April 2020
to mid-July 2021. ENISA, 2021.
[14] S. Labs Ltd, “Content Disarm and Reconstruction CDR Protection OPSWAT Deep CDR October 2023,” 2023. [Online]. Available:
www.linkedin.com/company/se-labs/
[15] N. Nissim, A. Cohen, and Y. Elovici, “ALDOCX: Detection of Unknown Malicious Microsoft Office Documents Using Designated
Active Learning Methods Based on New Structural Feature Extraction Methodology,” IEEE Transactions on Information Forensics
and Security, vol. 12, no. 3, pp. 631–646, 2017, doi: 10.1109/TIFS.2016.2631905.
[16] Microsoft Defender, “Macro malware in Microsoft Office documents,” https://learn.microsoft.com/en-us/defender
endpoint/malware/macro-malware.
[17] C. Smutz and A. Stavrou, “Network and Distributed System Security Symposium (NDSS),” in When a Tree Falls: Using Diversity in
Parsers to Detect File Format Vulnerabilities, San Diego, CA, USA: Internet Society, 2016.
[18] "Document Management-Portable Document Format-Part 1: PDF 1.7 PDF 32000-1:2008 ii,” 2008. [Online]. Available:
http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=51502.ItisbeingmadeavailablefromthewebsiteofA
dobeSystemsIncorporated
[19] "Document Management-Portable Document Format-Part 2: PDF 2.0 INTERNATIONAL STANDARD ISO 32000-2,” 2017.
[Online]. Available: www.iso.org
[20] C. Smutz and A. Stavrou, “When a Tree Falls: Using Diversity in Ensemble Classifiers to Identify Evasion in Malware Detectors,” in
23rd Annual Network and Distributed System Security Symposium, NDSS 2016, The Internet Society, 2016. doi:
10.14722/ndss.2016.23078.
[21] abuse.ch, “Malware Bazaar: A Malware Sharing Platform for Threat Intelligence.”