Files remember: GPS coordinates, device models, timestamps, author names β all hiding in metadata. ExifTool reads (and scrubs) it for forensics and OSINT alike.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Phones embed location history by default. Wild, right?
-r walks directories for bulk work.
Edited-by-what and timestamps form authenticity clues.
Privacy hygiene for your own uploads.
Stego/forensics challenges love hiding flags right here.
| -r | recursive |
| -all= | strip metadata |
| -GPS* | location fields |
| -csv/-json | machine output |
| Comment field | CTF hiding spot |
| -overwrite_original | edit in place |
Social images: strip GPS before posting β learn why the hard way is optional.
Documents leak author/org data: same tool, same lesson.
Pair with strings + binwalk for the full CTF-forensics handshake.
On IR: metadata timestamps help build attacker timelines.
Use ExifTool only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.