Extracting Metadata from Documents in Legendary OSINT: Metagoofil, FOCA, and Bulk Extractor

The Legendary OSINT repository recommends three specific open-source utilities for extracting metadata from documents: Metagoofil for harvesting public document metadata, FOCA for discovering embedded hidden data including GPS coordinates, and Bulk Extractor for forensic-grade analysis of files and disk images.

The K2SOsint/Legendary_OSINT knowledge base provides a curated collection of open-source intelligence tools, including dedicated utilities for extracting metadata from documents in Legendary OSINT workflows. According to the repository's automation and reconnaissance guide, three primary tools are explicitly listed for analyzing document metadata such as author information, creation dates, and hidden embedded data.

Document Metadata Tools Listed in Legendary OSINT

The docs/automation-recon.md file contains a "Metadata and Document Analysis" section (lines 24-28) that identifies three specific tools for this purpose. According to the Legendary OSINT source code, these are the only utilities explicitly cited for document-metadata extraction, distinguishing them from image-specific utilities like ExifTool that appear elsewhere in the repository.

Metagoofil

Metagoofil is designed to retrieve metadata from publicly accessible documents including PDFs, DOCX, and PPTX files. It extracts critical information such as author names, creation dates, and software versions that may be inadvertently exposed in public documents. The tool is referenced in the Legendary OSINT automation guide as the primary solution for metadata harvesting from public-facing files.

FOCA

FOCA (Fingerprinting Organizations with Collected Archives) scans documents for embedded metadata and generates consolidated reports. It supports a wide range of file types and can enumerate hidden data such as GPS coordinates, embedded URLs, and network paths that standard applications might not display. According to the source code in docs/automation-recon.md, FOCA is listed alongside Metagoofil as a core document analysis utility.

Bulk Extractor

Bulk Extractor is a forensic-oriented utility that extracts both raw data and metadata from files, images, and disk images. Unlike the other tools, it produces comprehensive CSV and JSON output suitable for large-scale forensic investigations. The repository documentation cites Bulk Extractor as the solution for scenarios requiring deep, automated data extraction across multiple file formats.

Command-Line Usage Examples

Below are minimal command-line snippets demonstrating how to invoke each tool against a sample PDF file (sample.pdf). These examples reflect the standard invocation patterns documented in the Legendary OSINT repository.


# Metagoofil – simple metadata dump

metagoofil -d . -f sample.pdf -t pdf -o output_metagoofil/

# FOCA – launch the GUI (or use command-line mode)

foca -i sample.pdf -o output_foca/

# Bulk Extractor – generate CSV with extracted metadata

bulk_extractor -o output_bulk_extractor/ sample.pdf

Source Documentation Location

The definitive reference for these tools appears in the repository's automation and reconnaissance documentation. Specifically, the docs/automation-recon.md file lines 24-28 contain the "Metadata and Document Analysis" section that lists these three utilities with brief descriptions and links to their respective GitHub repositories (laramies/metagoofil, ElevenPaths/FOCA, and simsong/bulk_extractor). The root README.md provides the index linking to this automation guide.

Summary

  • Metagoofil, FOCA, and Bulk Extractor are the three primary tools listed in Legendary OSINT for document metadata extraction.
  • These tools are documented in docs/automation-recon.md within the "Metadata and Document Analysis" section (lines 24-28).
  • Metagoofil targets public document metadata harvesting, FOCA specializes in hidden embedded data discovery, and Bulk Extractor provides forensic-grade extraction capabilities.
  • All three utilities support common document formats including PDF, DOCX, and PPTX.

Frequently Asked Questions

Which tools does Legendary OSINT recommend for extracting document metadata?

Legendary OSINT explicitly recommends three tools: Metagoofil for retrieving standard metadata from public documents, FOCA for discovering hidden embedded information like GPS coordinates and URLs, and Bulk Extractor for forensic analysis of files and disk images. These are the only utilities specifically cited for document metadata extraction in the repository's automation guide.

Can these tools extract GPS coordinates from documents?

Yes, FOCA specifically supports enumeration of hidden GPS coordinates embedded within document metadata, along with other concealed data such as embedded URLs and network paths. While Metagoofil focuses on standard metadata fields like author and creation date, FOCA specializes in uncovering these types of hidden geographic indicators.

Where is the metadata extraction documentation located in the repository?

The documentation for these tools is located in docs/automation-recon.md at lines 24-28 within the "Metadata and Document Analysis" section. This file is indexed in the root README.md and provides direct links to the GitHub repositories for Metagoofil, FOCA, and Bulk Extractor.

What file types are supported by these metadata extraction tools?

According to the Legendary OSINT source code, these tools support a wide range of document formats. Metagoofil handles PDFs, DOCX, and PPTX files commonly found in public repositories. FOCA supports an extensive list of file types for embedded metadata scanning. Bulk Extractor works with files, images, and disk images, making it suitable for comprehensive forensic analysis across multiple data sources.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →