File Metadata¶
Timestamps, properties, and embedded metadata that show where a file came from and what happened to it.
Why It Matters¶
Metadata answers questions the file contents do not: when a file was created or changed, who authored it, what software produced it, where a photo was taken, and whether a file was downloaded from the internet.
Reference¶
Viewing Metadata¶
| Task | Windows | Linux |
|---|---|---|
| Basic properties and timestamps | Right click -> Properties -> Details, or Get-ChildItem .\file.jpg | Format-List * |
stat <file> |
| Detailed listing | Get-Item .\file.jpg | Select-Object * |
ls -lisap <file> |
| Mark of the Web on a downloaded file | Get-Content .\file.exe -Stream Zone.Identifier |
|
| Embedded metadata (author, software, GPS) | ExifTool | ExifTool |
Zone.Identifier Values¶
| ZoneId | Zone |
|---|---|
| 0 | Local computer |
| 1 | Local intranet |
| 2 | Trusted sites |
| 3 | Internet |
| 4 | Restricted sites |
The stream can also record the ReferrerUrl and HostUrl, which show where a file was downloaded from.
How I Use It¶
For a suspicious file, I check the Zone.Identifier stream first: it shows whether the file came from the internet and often the exact URL. Then I run ExifTool for embedded metadata, which on documents can reveal the author name, the software used, and creation dates that do not match the story the file is telling.