Skip to content

ExifTool

Read, write and strip file metadata

VerifiedOSINT· Metadata & DocumentsBeginnerPerl-style (Artistic / GPL dual)Open sourceEntry revised 9 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Arch
  • Fedora
  • Docker
  • Source

Overview

8 commands documented

ExifTool reads and writes metadata across an enormous range of formats — EXIF, IPTC, XMP, GPS tracks, maker notes, document properties, video containers. It is the standard answer to 'what did this file carry with it'.

Two jobs dominate its use: investigation (what does this image reveal about the device, time and place it came from) and sanitisation (removing that information before publishing). Both directions work on the same command surface.

Supported platforms

9

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

metadata, exif, gps, privacy, forensics, sanitisation

Dataset entry

exiftool.ts

Reviewed 2026-01-09

Installation

Grouped by platform. Elevation requirements are marked per method.

Chocolatey

Recommendedchoco

Needs elevated privileges (sudo / Administrator).

choco install exiftool
  • Official ZIP archives and a Windows .exe build are also published on the site.

Official Windows executable

AlternativeinstallerOfficial

Rename to exiftool.exe, place on PATH, and call it from any directory.

Open official source

Package availability follows your distribution and enabled repositories. Entry revised 9 Jan 2026 — confirm the current release on the project's own download page.

Commands

8 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Dump every tag in a file

bash

Prints all metadata groups with their values, the usual first look at a suspicious file.

exiftool photo.jpg

02Human-readable, grouped output

bash

Adds computed values (aperture, exposure) and sorts by group so notes read cleanly.

exiftool -h -G1 photo.jpg

Notes

  • `-g1` groups by category with headers; `-h` prints friendly values; `-a` shows duplicate tags from different groups.

03Extract location tags only

bash

Pulls the GPS fields that matter for a place-of-origin question, including the rational values.

exiftool -G1 -a -n -geotag photo.jpg

Example output

Illustrative only — real output depends on the target, version and your position on the network.

[Exif-GPS] GPS Latitude : 52.5309
[Exif-GPS] GPS Longitude : 13.3846

Notes

  • `-n` prints numeric rather than sexagesimal values, which is what mapping tools expect.
  • A geotag proves nothing about *who* took the photo — only that a device wrote coordinates into the file.

04Summarise a whole evidence folder

bash

Recursively reports file type plus the tags that leak identity, into one text file for review.

exiftool -r -S -G1 -'all:author' -'all:artist' -'all:creator' -Directory -FileName -FileType . > case-metadata.txt

Notes

  • `-S` is 'very short' output (one line per tag), which pipes nicely into `sort | uniq -c`.

05Remove all writable metadata

bash

The standard sanitisation pass before publishing an image.

exiftool -all= -overwrite_original photo.jpg
  • This rewrites the file in place. `overwrite_original` skips keeping a `_original` backup, so run it on a copy or commit the originals first.

Notes

  • Some formats keep extra blocks (thumbnail, XMP, maker notes). Verify afterwards with `exiftool photo.jpg` rather than assuming success.

06Sanitise a directory while keeping structure

bash

Copies originals into an output tree and strips GPS, authorship and device identity from the copies.

exiftool -preserve -directory=clean -all= -'All>=' -XMP:all= -GPS:all= -Make= -Model= images/

Notes

  • `-preserve` keeps timestamps so later analysis of file dates remains possible.

07Machine-readable output for a pipeline

bash

Emit JSON so results feed a notebook, an evidence index or a diff between two versions of a document.

exiftool -json -r -G1 images/ > metadata.json

08Check documents before they leave

bash

Document formats carry author, company, revision history and embedded paths.

exiftool -G1 -a report.docx

Example output

Illustrative only — real output depends on the target, version and your position on the network.

[XMP-dc] Author : j.rivers
[ExifIFD] Software : Word 2019

Notes

  • Office files are ZIP containers: `exiftool` reads core properties, and `unzip -l` reveals what else is embedded.

Worked examples

Sequences of commands in the order they are used, with what you should expect to learn from each.

Preparing images for public release

A team is publishing press photos that came straight from a camera.

  1. 1

    See what would leak

    exiftool -r -G1 -comment -artist -copyright -city -gps:all press/
  2. 2

    Strip into a clean tree

    exiftool -preserve -directory=press-clean -all= press/*.jpg
  3. 3

    Verify the output is empty of identity tags

    exiftool -G1 -a press-clean/IMG_0412.jpg

Published files keep their visual content and timestamps without author, device or location metadata.

What it is used for

  • Source verification

    Compare a file's camera, software and date tags against its claimed origin.

  • Publication sanitisation

    Remove personal and location metadata before release.

  • Incident triage

    Spot authorship or embedded paths inside a delivered document.

  • Copyright checks

    Read IPTC/XMP rights fields in a batch of assets.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

'exiftool' is not recognized / command not foundCause 1/4

Possible causes

  • Installed via archive without adding to PATH, or the Perl package was installed as a library only.

Usual fix

On Windows, use the .exe on PATH or call the full path; on Linux confirm the package providing the binary (`dpkg -L libimage-exiftool-perl | grep bin`).

Metadata reappears after 'removing' itCause 2/4

Possible causes

  • Only one group was cleared, or the editor re-wrote tags when it saved.
  • Thumbnail or XMP block still contains a copy.

Usual fix

Use `-all=` across groups, add `-XMP:all=` and `-r` for embedded files, then re-check with `-a` to display duplicates.

exiftool -all= -XMP:all= -iframe:all= -overwrite_original file.jpg
"Warning: Sorry, format not recognized"Cause 3/4

Possible causes

  • Unsupported container, encrypted file, or an extension that does not match the content.

Usual fix

Identify the real type first (`file`, or `exiftool -j` on the raw bytes) and handle it as an unknown artefact rather than assuming corruption.

File timestamps changed, breaking an evidence chainCause 4/4

Possible causes

  • ExifTool updates file modification times by default.

Usual fix

Add `-api QuickTimeUTC`/`-P` (preserve) or `-preserve` and always work on copies of originals.

Tips

  • Always work on a copy when sanitising; `-overwrite_original` removes the safety backup the tool normally keeps.
  • `-a` plus `-G1` is the difference between seeing one author tag and seeing three conflicting ones.
  • Use `-json` for anything you will diff, and `-csv` when a reviewer wants a spreadsheet.
  • Metadata is corroborating evidence, never proof. Files can be re-saved, tags can be forged — say so in your notes.

Alternatives & comparisons

Not documented yet: ffprobe. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in OSINT