1 min read 271 words Updated Sep 12, 2026 Created Sep 12, 2026

online tools

StegOnline

exif and metadata viewer

aperosolve

forensic magnifier

metadata2go

DTMF decoder
DTMF is the audio tone that a phone keypress emits

command line tools

exiftool - inspect metadata
exiftool FILENAME

look for strings
strings FILENAME

binwalk
binwalk -Me FILENAME

extract data inside image files:
zsteg FILENAME

to extract data hidden inside an image file protected with a password
steghide extract -sf FILENAME

playbook:

File

file thisFile.txt
see what the computer thinks it is

Strings

View all strings in the file with strings filename.png

use -n 7 for strings of length 7+ ( or other number)
use -t x  to include line number / location in the file.

Exif / metadata

`exiftool FILENAME

Check file signature / magic bytes.

xxd FILENAME | head
make sure magic bytes match the file extension

PNG: 89 50 4E 47 0D 0A 1A 0A

JPEG: FF D8 FF

Wikipedia list of magic bytes

Binwalk

binwalk -Me filename.png.

Custom Example

pngcheck

you can use pngcheck to look for optional/correct broken chunks. This is vital if the image appears corrupt.

pngcheck -vtp7f filename.png to view all info.

v is for verbose, t and 7 display text chunks, p displays contents of some other optional chunks and f forces continuation after major errors are encountered.

Related write-ups:

steghide

Found a password? (Or not)

If you've found a password, the goto application to check should be steghide.
Bear in mind that steghide can be used without a password, too.

You can extract data by running:

steghide extract -sf filename.png