Introducing PRONOM syntax
Last updated on 2026-09-21 | Edit this page
Estimated time: 25 minutes
Overview
Questions
- Why does PRONOM need syntax?
- What syntax exists?
- What does the syntax enable us to do?
Objectives
- Understand how PRONOM-based identification works
- Write our first PRONOM compliant signatures
- Learn what a “BOF” is
Introduction to PRONOM syntax
- PRONOM needs syntax to enable the expression of format identification signatures
- Needs to articulate specific byte patterns, at specific locations
- Syntax has overlap with ‘Regular Expressions’ (RegEx) but is distinct from RegEx implementations in common code languages such as Java or Python
- Highly flexible!
Signatures and sequences
- Every File Format in PRONOM has a PRONOM Unique ID (PUID)
- A PUID can be associated with one or more signatures
- A PUID without any signatures will only identify based on its format extension
- A File Format ID tool will return a hit if any signature fully matches
- A signature consists of one or more ‘sequences’
- All sequences for a given signature need to match to return a hit
Signature syntax conventions
- Byte patterns use hexadecimal notation (but they don’t use a ‘0x’ prefix!)
- Byte patterns can’t use space characters: use ‘ABCD’, not ‘AB CD’
- Use upper case symbols in signature sequences: ‘AB12CD34’, not ‘ab12cd34’
Signature positions
- BOF: Beginning Of File - the signature sequence starts at, or near the beginning of the file
- EOF: End Of File - the signature sequence starts at, or near the end of the file
- Var: Variable - the signature sequence may be found anywhere within the file
- Offset - the position, relative to the BOF, or EOF, where the sequence begins. 0 is default, meaning no offset. Since an offset of 0 means ‘starting from the first byte’, an offset of 4 means ‘starting from the 5th byte’, or ‘after the 4th byte’
- Maximum Offset - A further offset, relative to the initial Offset value described above. The default is 0, meaning no further possible offset.
Position and offset examples
BOF, Offset 0, Maximum offset 0: The signature sequence starts at the very beginning of the file
BOF, Offset 4, Maximum offset 0: The signature sequence starts at exactly position 0x04, the 5th byte
BOF, Offset 0, Maximum offset 4: The signature sequence may start anywhere within the first 5 bytes
BOF, Offset 4, Maximum Offset 4: The signature sequence may start anywhere from byte 5 through to byte 9
EOF, Offset 4, Maximum Offset 0: The signature sequence ends exactly 4 bytes from the end of the file
EOF, Offset 4, Maximum Offset 4: The signature sequence may end anywhere from 4 bytes to 8 bytes from the end of the file
Challenge
- Where can the byte sequence appear for BOF, Offset 16, Maximum offset 16?
- Given a file wholly consisting of the bytes
AABBCCDD, which 2 of these PRONOM byte sequences would match?
- BOF, Offset 0, Maximum Offset 4: AABBCCEE
- BOF, Offset 2, Maximum Offset 0: CCDD
- EOF, Offset 0, Maximum Offset 0: EE
- Variable: BBCC
- Anywhere from byte 17 to byte 33
- 2 & 4. The file doesn’t contain the bytes 0xEE, which appears in the target sequences of both 1 & 3.
Most common syntax
| Syntax element | Intended use | Example |
|---|---|---|
| Literal sequence | Just a plain signature sequence that appears as-is | A1B2C3D4 |
Infinite wildcard: *
|
The following sequence will appear at any point further in the file | A1B2C3D4*E5F6A7B8 |
Precise wildcard: {n}
|
The following sequence will appear after exactly the number of bytes specified | A1B2C3D4{4}E5F6A7B8 |
Wildcard range: {m-n}
|
The following sequence will appear at some point between the number of bytes specified | A1B2C3D4{4-8}E5F6A7B8 |
Either/Or: (a|b)
|
The following sequence will be any of the sequences specified. Any number of sequences can be specified | A1B2C3D4(0D|0A|0D0A)E5 |
Byte range [a:b]
|
The next byte will be within the range specified | A1B2C3D4[A4:B0]E5 |
Most signature sequences will combine some or all of the above.
Less common syntax
| Syntax element | Intended use | Example |
|---|---|---|
NOT sequence: [!a]
|
The following byte value is not this byte | A1B2C3D4[!E5]F6 |
Wildcard with infinite range:
{m-*}
|
The following sequence will appear minimally after the first value specified, but otherwise anywhere else in the file | A1B2C3D4{4-*}E5F6A7B8 |
Single wildcard: ??
|
The following byte may have any value. This is functionally
equivalent to {1}
|
A1B2C3D4??E5F6A7B8 |
NOT Byte range [!a:b]
|
The next byte will not be within the range specified | A1B2C3D4[!A4:B0]E5 |
| Wildcards at a beginning of a BOF sequence, or end of an EOF sequence | This is functionally equivalent to specifying Offset/Maximum Offset, however this is not recommended |
{4}A1B2C3D4 or: {0-4}A1B2C3D4
|
PRONOM Simplified Cheatsheet
PRONOM terms, basic syntax and data model
Offset markers
BOF = Beginning of File
EOF = End of File
Var = Variable (anywhere in the file)
Offset/Max Offset = Exact or positional range in which a signature starts
Combining sequences
- As described earlier, a format can have many Signatures - matching any Signature will return a hit
- A Signature may consist of any number of BOF, EOF, and Var sequences. All sequences within a Signature must match to return a hit
- Any BOF, EOF, or Variable sequence can include any syntax elements described above
- Signature sequences must be logically positioned differently, so you couldn’t have two BOF sequences with offset 0, maximum offset 0 specifying distinct values because a single file could never hold two distinct sequences at the same position, but if two sequences had BOF, offset 0, maximum offset 128, then both sequences must appear within the first 128 bytes
- Most commonly, a signature sequence will only have a BOF sequence - this is fine!
- Be wary with purely Variable-positioned sequences - in isolation they will cause the whole of your files to be scanned, so it’s always best to include either a BOF or EOF as an ‘anchor’
PRONOM in Practice
The team at The National Archives have worked hard to create good resources for PRONOM research and development. The PRONOM in Practice guide is an important set of documents to follow up on after this tutorial.
Challenge
Here is a real-world signature example taken from PRONOM:
- Position type: Absolute from BOF
- Offset: 0
- Value:
FFD8FFE0{2}4A464946000100(00|01|02) - Position type: Absolute from EOF
- Offset: 0
- Maximum Offset: 65536
- Value: FFD9
What are some features of this signature that you can spot?
- There are two sequences, both BOF and EOF
- The EOF sequence has an offset range, so the sequence can be found anywhere within the last 65,536 bytes of the file
- The BOF sequence has a specific wildcard
{2} - and a three-choice either/or block
(00|01|02)
- A PRONOM file format (PUID) can be associated with more than one signature, but only needs to match one full signature to return a positive hit
- A signature can consist of multiple sequences, and all sequences must match to return a positive hit
- PRONOM syntax is a form of regular expression (regex), although distinct from regex implementations in Java, Python etc.
- PRONOM sequences can be anchored relative to the beginning of the file (BOF), the end of the file (EOF), or anywhere within the file (Variable), however it is best practice to include at least one BOF or EOF anchor to avoid unnecessary full scans of files
- PRONOM syntax can be combined in multiple ways
- Sometimes there is more than one way to write a signature