> For the complete documentation index, see [llms.txt](https://viperone.gitbook.io/pentest-everything/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://viperone.gitbook.io/pentest-everything/everything/everything-osint/metadata-osint.md).

# Metadata OSINT

### Metagoofil

**Github:** <https://github.com/opsdisk/metagoofil>

Metagoofil is a tool for extracting metadata of public documents (pdf,doc,xls,ppt,etc) available in the target websites. This information could be useful because you can get valid usernames, people names, for using later in brute force password attacks (vpn, ftp, webapps), the tool will also extracts interesting "paths" of the documents, where we can get shared resources names, server names, etc. [\[Source\]](https://github.com/exiftool/exiftool#readme)

```bash
metagoofil -d <Domain> -t <FileExtension> -o <DestinationFolder>
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FHyKuNAX39J9yLIgXfERC%2Fimage.png?alt=media\&token=2129ecfd-273c-49ed-8f77-5f330a79f593)

The collected files can then be run alongside `Exiftool` to extract meta data information.

### Exiftool

**Github:** <https://github.com/exiftool/exiftool>

Exiftool is an command line application used to read and write meta information for a large variety of files.

Below is a wild card execution on PDF files. As per the image we can see a large amount of information that has been pulled from the PDF file.

```bash
exiftool -r *.pdf as
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2F3ATvQala4uDLBxAuzQ1S%2Fimage.png?alt=media\&token=4ffc457e-1673-47d6-a7c7-9bb3efafae5b)

Grep can be used to pull only information we are interested in. This is a better suited option when dealing with a large amount of files.

```
exiftool -r *.pdf | egrep -i "Author|Creator|Email|Producer|Template" | sort -u
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2F51J775x0FNNZAbSEzLzO%2Fimage.png?alt=media\&token=6c3bf55f-6a2f-4e6d-bfb8-67b5b004e096)

A large amount of information has been redacted from the search results purposely by myself. However, the results show the documents have been created by multiple out of date software.

We are also able to see authors names and usernames which can then be used to correlate email address.

This kind of information can also be correlated with database breaches to potentially discover plaintext passwords for existing users.

## Web Tools

### MetaData2Go

**URL:** [https://www.metadata2go.com/](https://www.metadata2go.com)

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FuUfCXpL62H3uTuP3cqwb%2Fimage.png?alt=media\&token=0b34e929-95a8-4ed7-abe4-3226b6d13fe5)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://viperone.gitbook.io/pentest-everything/everything/everything-osint/metadata-osint.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
