Doing it for yourself
Last updated on 2026-09-21 | Edit this page
Overview
Questions
- Can you apply what you’ve learned?
Objectives
- Develop a signature.
- Create a signature file.
- Test the signature file against the workshop test files!
Doing it for yourself
Now that you’ve seen everything there is to know about writing file format signatures and plugging them in, it is time to write one!
If you are doing this in a workshop environment, follow this thread. If you are following along at home in a tutorial, then skip to the small exercise below to find a task that you can complete at home.
Workshop exercise
- Split into groups.
- Work together to create a signature.
- Plug it into DROID/Siegfried
- Good luck!
You can do it!
Many of us have been developing file format signatures for years now and so if you’re new to this you will likely have questions. Your mentors are available to help guide your efforts. There will also be an opportunity at the end to discuss how things went.
Quite ok!
Your task is to find an identification for the Quite OK Image format. Below you will find a specification and some sample files. Take a look at these in any order you wish to determine what may provde to be a good file format signature for this new file format!
Specification
- QOI Specification also online here.
Local exercise
The following challenge is simply to try and write a DROID compatible signature file that can be used to identify three byte sequences designed for this tutorial. There are sample files available, and all you have to do is match all three!
Develop a signature for the following and test it in DROID or Siegfried
56 45 52 53 49 01 4E 00 00 32 30 30 32 00 00 00 00 00 43 48 41 52 53 45 54 00 00 61 73 63 69 69 00 00 00 00 00 00 00 00 00 00 00 00 00 00 25 45 4F 46
56 45 52 53 49 02 4E 00 00 32 30 30 32 00 00 00 00 00 43 48 41 52 53 45 54 00 00 75 74 66 2D 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 25 45 4F 46
56 45 52 53 49 03 4E 00 00 32 30 30 32 00 00 00 00 00 43 48 41 52 53 45 54 00 00 75 74 66 2D 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 25 45 4F 46
There are a number of consistent pattterns you can probably use to identify this bytestream (file), there are no wrong answers on such a small sample so don’t worry. In real world research we will try and find a reasonable number of samples with enough variance to test the hypothesis that are our signature files.
One possible solution
56 45 52 53 49 (01|02|03) 4E 00 00 32 30 30 32 00 00 00 00 00 43 48 41 52 53 45 54 00 00 (61 73 63 69 69|75 74 66 2D 38) 00 00 00 00 {0-10} 00 00 00 00 00 00 00 00 00 00 25 45 4F 46
- (01|02|03) - we see versions change here so we use option syntax, this could also be a lexicographic check or a check for a single byte.
- (61 73 63 69 69|75 74 66 2D 38) - two character encodings are listed across three files so we choose between one or the other.
- {0-10} - there’s some arbitrary length information here where the files are otherwise the same. We don’t know how much this will vary so to be safe we’ve elected for zero to 10 bytes, but this could easily be limited to three, or changed to be a full variable length wildcard.
Formatted for the signature development utility
5645525349(01|02|03)4E0000323030320000000000434841525345540000(6173636969|7574662D38)0000 0000{0-10}0000000000000000000025454F46
As XML for testing with DROID/Siegfried
XML
<?xml version="1.0" encoding="UTF-8"?>
<FFSignatureFile xmlns="http://www.nationalarchives.gov.uk/pronom/SignatureFile" Version="1788520000" DateCreated="2026-09-04T11:06:40+00:00">
<InternalSignatureCollection>
<InternalSignature ID="1" Specificity="Specific">
<ByteSequence Reference="BOFoffset">
<SubSequence MinFragLength="6" Position="1" SubSeqMaxOffset="0" SubSeqMinOffset="0">
<Sequence>5645525349(01|02|03)4E0000323030320000000000434841525345540000(6173636969|7574662D38)0000 0000{0-10}0000000000000000000025454F46</Sequence>
</SubSequence>
</ByteSequence>
</InternalSignature>
</InternalSignatureCollection>
<FileFormatCollection>
<FileFormat ID="1" Name="FFDEV Workshop Signature" PUID="ffdev/1" Version="1.0" MIMEType="application/octet-stream">
<InternalSignatureID>1</InternalSignatureID>
<Extension>file</Extension>
</FileFormat>
</FileFormatCollection>
</FFSignatureFile>
Taking note of the extension
You can also record a file format extension in a signature file. If you correctly match the file format extension then tools like Siegfried and DROID will highlight that the file has the correct extension and if a file presents with the incorrect extension they will often warn about that as well.
Wrapping up!
If you have managed to identify the three sample files using your own signature file, congratulations!
If you’re still wrestling with it, take a look at the solution and see if you can plug it into Siegfried and make it work. Take note of how the solution works or how you think it works and have a think about what wasn’t quite working in your own answer.
We’ll wrap up in the next lesson.
- You’ve all the tools needed to write file format signatures.
- It might not always work.
- It will certainly take trial and error.
- Persevere and keep working on it.
- Practice makes perfect!