All integrations
ExifTool logo
// Tentacle Tool · Forensics

Cracken + ExifTool

Cracken runs ExifTool to pull every tag group — EXIF, XMP, IPTC, GPS, maker notes — out of image, audio, video, and document files in one command. It acts on the usernames, paths, and software versions hiding there.

Get started
// 01

Connecting ExifTool

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed on a Tentacle, then invoked during an operation (the agent can install and uninstall it mid-run)

Requires

A Tentacle running Linux or macOS. Free licence, nothing to purchase and no credentials to supply.

// 02

What Cracken gets from ExifTool

  • EXIF and GPS metadata blocks

  • Timed metadata — GPS tracks — read out of MOV, MP4, M2TS and AVI video

  • IPTC and XMP metadata blocks

  • MakerNotes from many digital cameras

  • C2PA JUMBF provenance, GeoTIFF, ICC Profile, Photoshop IRB, FlashPix, AFCP, ID3 and Lyrics3 blocks

  • GM PDR data from videos written by cars such as the Corvette and Camaro

  • A metadata diff between two files

  • Output as tab-delimited text, HTML, XML or JSON

// 03

What ExifTool does not do

ExifTool reads far more than it can write: its own supported-formats table marks OpenDocument files (ODT/ODS/ODP/ODG), Ogg/Opus audio, Open Type fonts and many container formats read-only (R) rather than read/write (R/W). It reads the metadata attached to a file, not the file's contents.

// 04

How Cracken uses ExifTool

  1. 01

    Collect the files

  2. 02

    Run ExifTool on the Tentacle

  3. 03

    Read the metadata and continue

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

Do I need to install ExifTool myself?

No; Cracken installs the free, open-source ExifTool on the Tentacle, the Kali-based container running on infrastructure you control, when an operation needs it.

Do files leave my environment when Cracken reads their metadata?

No; ExifTool reads files locally on the Tentacle, a container on infrastructure you control, so the files themselves are never copied out.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real ExifTool context.

See how Cracken runs ExifTool on a Tentacle you host, and proves what it finds end to end.