AUTHOR SYLHETYHACKVENGER · HANDLE THE-ERROR808
MetaPWN is a unified, single-file offensive security and metadata intelligence platform written in pure Python. It consolidates universal metadata extraction, web and protocol reconnaissance, credential attacks, exploitation primitives, post-exploitation, cloud and container abuse, digital forensics, OSINT, and image and media analysis into a single interactive operator console.
Every capability is exposed as a module grouped under one of 46 pillars (A → AT). Modules auto-register on import, dispatch by target type, and persist artifacts into structured per-pillar input/ and output/ trees. Reports are emitted in JSON, CSV, XML, STIX 2.1, and MISP formats.
Table of Contents
· Highlights · Architecture · Pillar Reference · Installation · Quick Start · Command Reference · Reports & Artifacts · Data Layout · Extending MetaPWN · Optional Dependencies · Safety Features · Legal Notice
Highlights
Category Capability Formats 150+ file formats across documents, media, images, archives, mobile, binaries, and forensic images Pillars 46 pillars, 600+ modules, single-file deployment Targets URL, domain, IP, port, file path, hash, token, JWT, GPS coordinates Dispatch Auto-classification and auto-routing to relevant pillars Reports JSON, CSV, XML, STIX 2.1, MISP, partial-on-interrupt Runtime Rate limiting, HTTP cache, cookie jar, checkpointing, graceful shutdown Extensibility Drop-in Python plugins, JSON rule engine, scope file, kill switch Dependencies Pure Python core, optional libs degrade gracefully
Architecture
┌─────────────────────────────────────────────────────────────────────┐
│ MetaPWN REPL │
│ (Interactive Operator Console) │
└────────────────────────────────┬────────────────────────────────────┘
│
┌────────────▼────────────┐
│ Target Classifier │
│ Auto-Dispatch Router │
└────────────┬────────────┘
│
┌────────────────────────┼────────────────────────┐
│ │ │
┌────▼────┐ ┌────▼────┐ ┌────▼────┐
│ Web │ │ File │ │ Host │
│ Targets │ │ Targets │ │ Targets │
└────┬────┘ └────┬────┘ └────┬────┘
│ │ │
└────────────────────────┼────────────────────────┘
│
┌────────────▼────────────┐
│ Module Registry │
│ (46 Pillars A → AT) │
└────────────┬────────────┘
│
┌────────────────────────┼────────────────────────┐
│ │ │
┌────▼────┐ ┌────▼────┐ ┌────▼────┐
│ Engine │ │ Findngs │ │ Report │
│ Core │─────────────▶│ Store │─────────────▶│ Adapter │
└─────────┘ └─────────┘ └─────────┘
│
┌───────────┼───────────┐
│ │ │
JSON STIX MISP
CSV XML Partial
Runtime pipeline
Input → Classify → Route → Execute → Collect → Aggregate → Export
Pillar Reference
MetaPWN organizes its capabilities into 46 pillars, each handling a distinct domain of the offensive security and forensic lifecycle.
Pillar Name Domain Modules A EXTRACTOR Universal metadata from structured formats 45 B WEB/PROTO Web and protocol metadata 19 C SNATCHER Active retrieval 33 D CRACKER Hash, archive, and password recovery 27 E INTEL Cross-cutting intelligence 10 F ENGINE Plugins, rules, and output adapters 14 G CREDS Credential attacks 14 H EXPLOIT Exploitation primitives 18 I PRIVESC Privilege escalation 12 J PERSIST Persistence mechanisms 13 K LATERAL Lateral movement 13 L EXFIL Exfiltration channels 15 M PAYLOADS Payload generation 15 N C2 Command and control 12 O ANTI-FOR Anti-forensics 7 P CLOUD/CTR Cloud and container abuse 8 Q DOWNLOAD Universal retrieval 38 R RECOVERY Deleted-file and disk recovery 15 S CARVE Stream carving 13 T MEDIA-META Video and audio container extraction 22 U SOCIAL Social media metadata 16 V REMAINDER Remaining platforms and formats 20 W ARCHIVE Web archives and crawl indexes 16 X PEOPLE/PAY People intelligence and payment fingerprinting 17 Y GEO/CRED Geolocation and web credential extraction 19 Z OFFICE-DEEP Office and PDF deep analysis 20 AA MEDIA-DEEP Media container deep analysis 20 AB MOBILE Mobile app analysis 19 AC CONTAINERS Containers and Kubernetes 20 AD AD/KERB Kerberos, NTLM, and Active Directory 19 AE CLOUD-DEEP Deep cloud provider enumeration 25 AF CI/CD CI/CD pipeline metadata 25 AG DATABASES Database configuration and metadata 25 AH MSG-QUEUES Message queues and brokers 20 AI SECRETS Secret and token validation 20 AJ SYSTEMD systemd and journald forensics 15 AK BROWSER-ART Browser artifacts deep 20 AL FORENSICS Windows, macOS, and Linux forensics 30 AM ICS/VOIP ICS, telecom, and VoIP 20 AN HARDWARE Printers and hardware inventory 25 AO WIRELESS Bluetooth and nearby radio 15 AP OS-LINUX Linux system enumeration 20 AQ WEB-DEEP Web application deep analysis 20 AR WEB-INTEL Web intelligence and scraping 25 AS INFRA Infrastructure service configs 25 AT PICTURE Image metadata and forensic analysis 96
Detailed Pillar Capabilities
A — EXTRACTOR · Universal metadata from structured formats
· OpenDocument (odt/ods/odp) meta.xml · RTF info group, EPUB OPF, MOBI/AZW3 Kindle blocks · Apple iWork (Pages/Numbers/Keynote), OneNote .one · Visio, MS Project .mpp, Publisher .pub, Access .mdb/.accdb · AutoCAD .dwg/.dxf, Photoshop .psd, Illustrator .ai, InDesign .indd · Sketch/Figma exports, Blender .blend, Unity .unity3d · Subtitles .srt/.ass, iCalendar .ics, vCard .vcf, Torrent .torrent · Apple plists, Windows .lnk, Prefetch, Registry hives, .evtx, .DS_Store · SQLite schema + PII scan, MongoDB BSON, LDIF, .eml/.msg/.pst/.ost · SBOM (SPDX / CycloneDX), JAR/APK/IPA/WAR manifests · .NET assembly, Go/Rust/GCC build info, PE/ELF/Mach-O headers · Firmware blobs, QR + barcode + OCR, PDF Info + XMP + JS · DOCX/XLSX/PPTX docProps, ID3v2 frames, native XMP sidecars
B — WEB/PROTO · Web and protocol metadata
· HTTP response header fingerprinting, meta-tag mining · , RSS/Atom, OpenGraph + Twitter Card · JSON-LD structured data, GraphQL introspection · Swagger / OpenAPI discovery, WSDL/SOAP, GraphQL SDL · favicon mmh3 (Shodan), TLS certificate metadata (SANs, PEM save) · DNS records (A/AAAA/MX/NS/TXT/CNAME/SOA/CAA/SRV/DMARC) · WHOIS / RDAP registrant, HTTP/2 + HTTP/3 push headers · Cookie metadata, CORS misconfig, JWT payload decode, secret regex sweep
C — SNATCHER · Active retrieval
· Browser cache/history/cookie DB discovery, session token snatch · OS credential manager enumeration, SSH key metadata · Git repo scraping (.git/.svn/.hg), .env recursive parse · Docker registry metadata, Kubernetes manifest leaks · Cloud IMDS (AWS/GCP/Azure/DO/Alibaba/Oracle), SSRF → IMDS · Cloud storage enumeration (S3/GCS/Azure), open bucket discovery · Slack/Discord/Teams webhooks, Postman/Insomnia, Jupyter notebooks · Elasticsearch/Kibana, MongoDB/Redis/Memcached/CouchDB · RabbitMQ/Kafka/MQTT, Jenkins/GitLab/Gitea · SonarQube/Nexus/Artifactory, WordPress/Drupal/Joomla · Paste site monitor, Wayback diffing, AXFR, NSEC walking · Reverse IP pivot, ASN enum, subdomain brute force
D — CRACKER · Hash, archive, and password recovery
· Hash identification (MD5/SHA/NTLM/bcrypt/argon2/yescrypt/SSHA) · Dictionary attacks with hashcat fallback hints · ZIP/RAR/7z/PDF/Office password recovery · JWT secret brute force, Basic-auth, form-login brute force · Steganography detection + recovery (steghide) · EXIF hidden-data carve, polyglot detection, embedded file carving · Base64/hex/URL/ROT13 auto-decode, multi-layer recursive decode · XOR single-byte brute, Vigenère auto-crack, Caesar, rail fence · QR/barcode decode, OCR, wire fuzz, SSRF, XXE, path traversal
E — INTEL · Cross-cutting intelligence
· Unified timeline (HTTP + filesystem + findings) · Entity graph (emails → domains → IPs → URLs) · Dedup SHA256 + fuzzy hash (ssdeep, tlsh) · Language detection, named entity recognition · Secret scanning ruleset, PII detection · YARA-style signature scan, IOC extraction, MITRE ATT&CK mapping
F — ENGINE · Plugins, rules, and output adapters
· Plugin loader (data/plugins/*.py) · Rule engine (data/rules.json) · Output adapters (JSON / CSV / XML / STIX 2.1 / MISP) · Resume/checkpoint, distributed mode (worker + coordinator) · Docker image + compose generator, REST API mode · TUI/Web UI helpers, live streaming output · Phase skipping, scope file, kill switch, encrypted output vault
G — CREDS · Credential attacks
· Password spraying, credential stuffing · Username permutation engine, email → username mapping · Default-credential testing, SSH key harvesting · Kerberos username enum, AS-REP roast, Kerberoast · NTLM relay prep, JWT forgery (alg:none + HS256 guesses) · API key replay, OAuth token replay, session cookie hijack
H — EXPLOIT · Exploitation primitives
· Version → CVE mapping, searchsploit lookup · SSRF chains, XXE delivery, path traversal chains · Log4Shell / Spring4Shell probes, deserialization gadget detection · Web shell drop, SQLi autopwn, Cmdi autopwn, SSTI autopwn · File upload bypass, GraphQL mutation abuse · Mass assignment, prototype pollution, race-condition, subdomain takeover · DNS rebinding, S3 bucket hijack
I — PRIVESC · Privilege escalation
· Linux SUID/sudo/cron checks, Windows service checks · Container escape (/.dockerenv, docker.sock, cgroups) · Kubernetes privesc, cloud IAM privesc, IMDS privesc · SSH agent forwarding abuse, Kerberos delegation abuse · ADCS abuse, GPO abuse, Sudo CVE, Polkit PwnKit
J — PERSIST · Persistence mechanisms
· authorized_keys injection, cron / systemd timers · Windows scheduled task, registry Run key, WMI subscription · Web shell persistence, reverse-shell beacon (bash + PS) · Service install, cloud backdoor, container sidecar injection · Backdoor in build pipeline, DNS-based persistence, LDAP persistence
K — LATERAL · Lateral movement
· Pass-the-hash, pass-the-ticket, overpass-the-hash · PSExec / SMBExec / WMIExec / ATExec / DCOMExec · WinRM / RDP spray, SSH pivot, SOCKS proxy over host · Cloud lateral, VPN lateral, Kubernetes lateral · Internal DNS poisoning, network share enum, DB hop
L — EXFIL · Exfiltration channels
· DNS tunneling, ICMP covert channel, HTTPS exfil · Cloud storage exfil, paste site exfil, stego exfil · Encrypted archive exfil, chunked exfil with timing jitter · Exfil via chat webhooks, backup service, print jobs, email · Exfil via GitHub, DNS zone, monitored-API blending
M — PAYLOADS · Payload generation
· Reverse shell generator (bash/nc/python/perl/powershell/socat) · Shellcode encoder (XOR + Base64) · PE / ELF payload builder, cross-compile support · Macro (VBA), LNK, HTA, JScript, VBScript generators · One-liner obfuscator, PowerShell AMSI bypass · AV evasion stub, signed binary proxy list · DLL sideloading payload, container image backdoor · K8s job template, CloudFormation / Terraform backdoor
N — C2 · Command and control
· Reverse shell listener, HTTP/HTTPS C2 server · DNS C2, Slack/Discord/Telegram C2 · GitHub-based C2, dead-drop C2, session management · Post-exploitation modules, screen/webcam capture · Keylogger module, credential dumper, screenshot/clipboard
O — ANTI-FOR · Anti-forensics
· Log wiping, timestamp manipulation, shell history clearing · Process name masquerading, traffic shaping · Certificate pinning bypass (Frida), AV/EDR evasion hints
P — CLOUD/CTR · Cloud and container abuse
· AWS/Azure/GCP abuse scripts + live identity probes · Kubernetes abuse, Docker abuse, CI/CD pipeline injection · Serverless hijack, IaC state file leak
Q — DOWNLOAD · Universal retrieval
· HTTP/HTTPS streaming, segmented multi-connection, resume · Checksum verification, bandwidth throttling, size cap · Cookie jar (Netscape), FTP/FTPS, SFTP, SCP, TFTP, WebDAV · SMB / CIFS, NFS, S3, GCS, Azure Blob · BitTorrent / magnet, HLS (m3u8), DASH (mpd) · RTSP live capture, RTMP live capture, Git clone · Recursive website crawler, sitemap-driven bulk download · Link extractor, download queue with concurrency · aria2c, wget, curl, yt-dlp, gallery-dl, rclone, lftp wrappers
R — RECOVERY · Deleted-file and disk recovery
· NTFS deleted-file recovery (MFT), ext2/3/4 recovery, FAT/exFAT · PhotoRec-style carving, SQLite WAL/journal recovery · Windows $Recycle.Bin recovery, shellbag parsing, jump lists · macOS quarantine events, Linux log recovery · Memory dump (Volatility), registry hive recovery · Volume shadow copy access, trash recovery · Browser closed-session recovery
S — CARVE · Stream carving
· Carve socket traffic, command output (pipe), PCAP streams · Printable strings + UTF-16 strings · DNS-tunneled exfil data, raw disk images · HTTP responses from proxy logs, credentials from memory dumps · Encryption keys, URLs and endpoints · Base64 blobs (auto-decode to known magic) · XOR-encoded payloads (256-key brute with magic match)
T — MEDIA-META · Video and audio container extraction
· ExifTool universal extraction, ffprobe, MediaInfo, mkvinfo · 7z + unrar listings · Native MP4/MOV, MKV/WebM, AVI, WAV/BWF, MP3 ID3, FLAC, OGG/Opus, WebP · Native HEIC/AVIF, SVG, XMP, NFO, GPX, KML, TIFF IFD · Universal metadata auto-dispatch
U — SOCIAL · Social media metadata
· oEmbed autodiscovery, YouTube, Vimeo, TikTok, Instagram, Twitter/X, Facebook · Reddit, Schema.org VideoObject, OG video tags · Plex/Jellyfin/Kodi NFO, HLS/DASH manifest metadata · Streaming player metadata, embedded video extraction · Media catalogue API (Plex/Jellyfin), download-and-inspect video
V — REMAINDER · Remaining platforms and formats
· LinkedIn, Pinterest, Tumblr post metadata · Mastodon status, Bluesky AT Protocol, Mastodon instance info · ActivityPub actor lookup, RAW camera (CR2/NEF/ARW/DNG/ORF/RW2) · CHM, DjVu, FB2, CBZ/CBR, mind maps (.mm/.xmind/.mindnode) · Native RAR / 7z / TAR (PAX/GNU) header parsers · ISO 9660 / UDF / El Torito, NTFS MFT, ext superblock, Shellbag
W — ARCHIVE · Web archives and crawl indexes
· Wayback CDX URL enumeration, subdomain enum, historical robots.txt · Wayback availability + snapshot retrieval · Internet Archive item metadata / advanced search / collection search · Common Crawl URL index, digest lookup, WARC byte-range retrieval · Memento TimeMap, Memento aggregator discovery · archive.today lookup, search engine cache lookup
X — PEOPLE/PAY · People intelligence and payment fingerprinting
· Employee name enumeration, email naming convention inference · Candidate email generation, GitHub commit email extraction · GitHub org member enum, SMTP RCPT verification · Cross-platform username correlation (18 services) · Breach database correlation (HIBP), people search site links · Payment gateway frontend fingerprint, e-commerce platform detection · Payment orchestration layer detection, leaked payment credential search · PSP API key pattern matching, checkout flow analysis · Merchant risk signals, payment SDK version detection
Y — GEO/CRED · Geolocation and web credential extraction
· Forward/reverse geocoding (Nominatim), IP geolocation · WiFi BSSID geolocation (WiGLE), cell tower geolocation (OpenCellID) · EXIF GPS extraction + enrichment · Satellite imagery metadata, Street View capture, elevation lookup · Timezone resolution, Overpass radius search · Location history / trajectory reconstruction · Web username/password extractor, login form detection · Basic-auth header extractor, hidden input + comment extraction · HTML metadata credential sweep, form login brute force
Z — OFFICE-DEEP · Office and PDF deep analysis
· DOCX full XML tree dump, XLSX all sheets, PPTX slide metadata · DOCX embedded fonts, tracked changes · XLSX defined names, external links, hidden sheets, VBA macros · PDF embedded objects, annotations, forms, incremental updates · PDF encryption and permissions · ODT styles, iWork preview, OneNote sections · Visio stencils, MS Project tasks, Publisher pages
AA — MEDIA-DEEP · Media container deep analysis
· MP4 subtitle/audio/video tracks, chapters, fragmented files, reference movies · MKV chapters + attachments, AVI stream headers · WAV cue points, BWF broadcast metadata · FLAC cue sheet + PICTURE block, Ogg stream info · WebP ICC profile, HEIC/AVIF item info · SVG CSS + scripts, XMP full dump · Photoshop layers, TIFF EXIF IFD, RAW camera metadata
AB — MOBILE · Mobile app analysis
· APK permissions, activities/services, resources, signing certs · APK assets/native libs, DEX classes, base64 strings · IPA Info.plist, provisioning, frameworks, entitlements · Xamarin / React Native, Flutter libapp.so, Unity assets · Cordova/PhoneGap config, native library list · APK version/target SDK, permissions risk scoring
AC — CONTAINERS · Containers and Kubernetes
· Docker image config, layer commands, labels and env · Compose file parser, K8s deployment YAML, K8s secrets decoder · K8s service account tokens, Helm chart, Terraform state · CloudFormation, Ansible, Vagrant, Packer, Serverless framework · Nomad, Kustomize, Dockerfile, container env dump, cgroup limits · OCI image manifest
AD — AD/KERB · Kerberos, NTLM, and Active Directory
· ccache, kirbi ticket parsing, krb5.conf, krb5.keytab · NTLM hash extraction from SAM, Kerberoast, AS-REP roast · KDC probe, LDAP anonymous bind, LDAP root DSE dump · AD domain info, AD users, PAC parsing · NTLM challenge extraction from PCAP · Kerberos realm discovery, AD CS templates, AD trusts · gMSA password read, NTLM relay targets
AE — CLOUD-DEEP · Deep cloud provider enumeration
· AWS IAM users, S3 buckets, EC2 instances, Secrets Manager, SSM, Lambda · GCP projects, service accounts, storage buckets · Azure tenants/subscriptions, storage accounts, Key Vault · Kubernetes pods, services, cluster roles, configmaps · Cloud instance identity, cloud-init user data · IMDSv1 (AWS), GCP metadata server, Azure IMDS · DigitalOcean / Alibaba / Oracle metadata, cloud storage signed URLs
AF — CI/CD · CI/CD pipeline metadata
· GitHub Actions, GitLab CI, Jenkins, CircleCI, Travis, Drone · Tekton, Argo Workflows, Buildkite, Woodpecker, Bamboo · AppVeyor, Azure Pipelines, Dependabot, Renovate · GitLab CI secrets, GitHub Actions secrets in logs · Artifactory build info, Nexus repositories, CI runner tokens · Build artifact signatures, pipeline env vars, SBOM in CI · CI badge metadata, release asset metadata
AG — DATABASES · Database configuration and metadata
· MySQL / Postgres pg_hba / Redis / Elasticsearch / Cassandra / RabbitMQ / Kafka · SQL Server config, SQLite discovery, pg_hba.conf · DB connection string sweep, live Redis INFO · MongoDB isMaster, Memcached stats, Cassandra cqlshrc · InfluxDB / CouchDB / Neo4j config · DB error page detection, MSSQL xp_cmdshell, MySQL UDF · Postgres extensions, Redis keys dump, Elasticsearch index dump
AH — MSG-QUEUES · Message queues and brokers
· RabbitMQ management API, Kafka topics, MQTT broker probe · NATS monitoring, ZeroMQ, ActiveMQ, Solace PubSub+ · Google PubSub emulator, Pulsar admin, Celery broker, RocketMQ · AWS SQS / SNS / Kinesis, Azure Service Bus / Event Hubs, GCP PubSub · RabbitMQ shovel/federation, Kafka topic config, MQ credentials sweep
AI — SECRETS · Secret and token validation
· GitHub, AWS (AKIA pair), Google API, Slack, Stripe, SendGrid · Twilio, JWT full parse, TOTP secret extraction · GitLab, NPM, PyPI, Docker registry, DigitalOcean, Heroku · Cloudflare, OpenAI, HuggingFace, Discord bot, Telegram bot
AJ — SYSTEMD · systemd and journald forensics
· Unit files, journal dump, journal JSON fields · systemd-networkd, resolved, timesyncd configs · coredumpctl, tmpfiles rules, timers, failed services · Service env files, coredump pattern, socket units, path units, drop-ins
AK — BROWSER-ART · Browser artifacts deep
· Chrome extensions, Local Storage, IndexedDB, Service Worker cache · Firefox addons, places.sqlite, logins.json, cookies.sqlite · Chrome Login Data cookies, Web Data autofill, Shortcuts, Top Sites · Safari history + cache, Edge profile, Brave rewards · Search engines, sync accounts, download history · Chrome extension cookies, Firefox formhistory
AL — FORENSICS · Windows, macOS, and Linux forensics
· Prefetch, Amcache, ShimCache, USB history, RecentDocs · MUICache, UserAssist (ROT13), Windows Search, thumbcache · Windows event log parsing, $MFT, USN Journal, $LogFile · Recycle bin $I metadata, Windows Timeline activitiescache.db · Windows notifications, Defender scan history · PowerShell + Bash history, RDP bitmap cache, WiFi profiles · Clipboard history, LSA secrets, WMI repo, startup items, services · macOS unified log, LaunchAgents/Daemons, TCC db, knowledgeC.db
AM — ICS/VOIP · ICS, telecom, and VoIP
· Modbus, DNP3, BACnet, Siemens S7comm, EtherNet/IP CIP · OPC-UA, PROFINET DCP, Zigbee sniff, Z-Wave · LoRaWAN, SIP, RTP, H.323, MGCP, SS7/SIGTRAN · Diameter, GTP-C/GTP-U, SCTP assoc, RADIUS, Diameter CER
AN — HARDWARE · Printers and hardware inventory
· IPP printer attributes, PJL printer info, LPD queue info · HP / Brother / Canon / Xerox printer MIBs, config page · Print job spool, CUPS config, USB / PCI trees · Block devices, DMI/SMBIOS, UEFI vars, memory modules · CPU, GPU, battery, sensors
AO — WIRELESS · Bluetooth and nearby radio
· Bluetooth device scan, paired devices, adapter info · Nearby WiFi networks, saved WiFi credentials · GPS device discovery, NFC tag reading, RFID reader probe · SDR device info, WiFi monitor mode, airodump-ng survey · WPS APs, Bluetooth LE scan, GATT services, Zigbee coordinator
AP — OS-LINUX · Linux system enumeration
· /etc/passwd, /etc/group, sudoers, capabilities · systemd services, kernel modules, sysctl · iptables / nftables, resolved, mounts, env vars · Process tree, open files, kernel params · SELinux/AppArmor, /etc/shadow (root), interfaces · /etc/hosts, logind sessions
AQ — WEB-DEEP · Web application deep analysis
· robots.txt, sitemap.xml, security.txt, humans.txt, ads.txt · HTTP security headers score, CSP parse · Open redirect test, HTTP method enum, directory listing detection · Backup file discovery, source map discovery · WAF detection, reverse proxy detection, load balancer detection · Cookie SameSite / Secure analysis, content-type handling · HTTP caching headers, compression and encoding
AR — WEB-INTEL · Web intelligence and scraping
· Cloudflare email protection decode, base64 email obfuscation · Comment email scraping, JavaScript email scraping · Contact form fields, social media links, BTC/ETH addresses · Phone / address scraping, employee names from team pages · RSS feed discovery, Google Analytics IDs · Facebook Pixel, Adsense, Disqus, reCAPTCHA site keys · Stripe publishable keys, Google Maps key, Slack workspace · GitHub org profile, LinkedIn slug, Twitter handle guess · Reddit subreddit, Wikipedia page scrape, Common Crawl backlinks
AS — INFRA · Infrastructure service configs
· Docker Compose port mapping, Nginx sites, Apache vhosts · HAProxy, Envoy, Traefik, Caddy · WireGuard, OpenVPN, IPsec · Keepalived, Consul, Nomad, Vault, etcd, Zookeeper · Hadoop, Spark, NFS exports, Samba, iSCSI targets · ZFS, Btrfs, LVM, RAID
AT — PICTURE · Image metadata and forensic analysis
The deepest pillar in MetaPWN, covering the complete image forensics lifecycle.
Core metadata — Basic info, format detection, ICC color profile, thumbnail extraction, dominant color / palette, full EXIF dump, camera make/model/lens/serial, EXIF dates, GPS, altitude/direction, shooting settings, orientation, white balance, UserComment, Software/Firmware.
Geo enrichment — GPS reverse geocoding, elevation lookup, timezone resolution, Street View URL, satellite tile, trajectory from multiple images, geotag clustering.
Ownership — Artist / Creator / Copyright, XMP owner, dc:creator + dc:rights, IPTC creator/contact, Photoshop owner metadata, Lightroom settings, Google/Apple Photos metadata.
Timeline — Full timestamp history, Photoshop history / edit trail, filesystem timestamps, XMP edit history, software edit chain.
Steganography — Appended data detection, steganography detection (LSB/steghide), palette steganography, EXIF thumbnail mismatch, double JPEG compression detection.
Content — QR code, face detection, barcode/QR, OCR, screenshot metadata + URL leak, sensitive text in image (SSN/CC/IBAN).
Container analysis — JPEG segments, PNG chunks, GIF logical screen + frames, BMP header, ICO/CUR, JPEG2000, JPEG XL, QOI, FLIF, DDS, TGA, PSD layers, ICO frames deep, SVG element census / embedded raster / external refs.
Modern formats — C2PA / Content Credentials manifest, IPTC IIM fields, maker notes, GPS deep, HEIC auxiliary images, JPEG XT / HDR metadata, APNG info, animated WebP, AVIF sequence.
Analysis — Perceptual hash (pHash/aHash/dHash/whash), custom dHash64, reverse image search link generation, SSIM similarity, burst/sequence detection, EXIF completeness score, EXIF anomalies, metadata stripping verification, GIF frame timestamps.
Reporting — JPEG APP marker deep scan, bounding box / crop detection, histogram statistics, color histogram, sharpness/blur estimate, screenshot vs camera classification, embedded preview extraction, MIME/magic verification, comprehensive report, HEIC/AVIF thumbnails, PSD resources, xattr/ADS scan, image URL/host leak, metadata diff, final image intelligence rollup.
Installation
Prerequisites
· Python 3.9+ · Linux, macOS, or Windows (Linux recommended) · Optional root for automatic bootstrap
Clone
git clone https://github.com/THE-ERROR808/MetaPWN.git
cd MetaPWNBootstrap (recommended)
Run once as root to install all optional system packages and Python libraries:
sudo python3 1.pyThe bootstrap installer provisions:
· apt packages — exiftool, ffmpeg, mediainfo, mkvtoolnix, 7z, unrar, tesseract, steghide, binwalk, foremost, sleuthkit, testdisk, hashcat, john, hydra, sqlmap, nmap, dig, whois, curl, wget, git, aria2, rclone, smbclient, snmpwalk, and more · pip packages — aiohttp, beautifulsoup4, lxml, PyPDF2, openpyxl, python-docx, python-pptx, olefile, Pillow, pyzbar, timezonefinder, pysmb, smbprotocol, ssdeep, tlsh, msoffcrypto-tool, python-magic, pefile, dnspython, pyOpenSSL, cryptography, yara-python, ipwhois, pytesseract, svglib, reportlab, icalendar, vobject, exifread, hachoir, pyasn1, pyasn1-modules, pyyaml, piexif, imagehash, psd-tools
Manual install
pip install -r requirements.txt # or install individuallyMetaPWN degrades gracefully — modules automatically skip when a dependency is missing.
Quick Start
python3 1.pyExample session
MetaPWN› target https://example.com
MetaPWN› B
MetaPWN› findings 100
MetaPWN› save
Target types
Target Example URL target https://example.com Domain target example.com IP / port target 10.0.0.1:443 Local file target ./evidence/photo.jpg Hash target 5d41402abc4b2a76b9719d911017c592 JWT target eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... Coordinates target 40.7128,-74.0060
MetaPWN auto-classifies and routes the target to the relevant pillars.
Command Reference
Target management
Command Description target Set target (auto-classified + auto-copied) target Show current target clear Clear target info Show target type and routing autocopy Copy target into pillar input trees
Module execution
Command Description Run module by numeric ID Run all modules in a pillar (e.g. A) -all Run every pillar from A to AT chain A B C Run pillars in sequence run Run every module matching pattern all Run every registered module
Listing
Command Description show List all modules grouped by pillar show List modules for a single pillar show Filter modules by keyword pillars List all pillars with descriptions count Total registered modules
Findings & reports
Command Description findings [N] Show last N findings save Write JSON / CSV / XML / STIX / MISP reports artifacts List generated artifacts clearfindings Wipe in-memory findings
System
Command Description help / ? Command reference banner Reprint banner deps Optional dependency status tools External tool availability env Environment variables cols Set terminal width shell Run a shell command python Evaluate a Python expression history Command history about Credits and version info exit / quit / q Leave MetaPWN
Prefix any command with ! to force raw shell execution, ? for quick help.
Reports & Artifacts
Reports are written to data/reports/:
Format File Purpose JSON report.json Full structured output CSV report.csv Spreadsheet-friendly tabular export XML report.xml Legacy integration STIX 2.1 report.stix.json Threat intelligence sharing MISP report.misp.json MISP event import Partial partial_.json Written on Ctrl+C
Every finding is also appended to data/metapwn.log as newline-delimited JSON.
Data Layout
data/
├── input_files/ # Auto-sorted by detected type
│ ├── documents/ media/ images/ archives/
│ ├── mobile/ binaries/ tokens/ strings/
│ ├── ip/ disk_images/ pcaps/ forensic/
│ ├── metadata/ office/ social/ web/
│ ├── geo/ emails/ misc/
├── pillars/
│ ├── A_EXTRACTOR/
│ │ ├── input/ # Drop files here
│ │ ├── output/ # Results land here
│ │ └── README.txt
│ ├── B_WEB-PROTO/
│ └── ... (through AT_PICTURE)
├── reports/ # JSON / CSV / XML / STIX / MISP
├── logs/ # session_<timestamp>.log
├── assets/ # Generated payloads, C2, cloud, shells
├── payloads/ # Reverse shells, encoders, stubs
├── wordlists/ # Built-in + drop your own
├── templates/
├── plugins/ # Drop .py plugins here
├── test_samples/
├── cookies.txt # Netscape cookie jar
├── scope.txt # allow / deny directives
├── rules.json # Rule engine
├── checkpoint.json # Resume state
├── metapwn.log # JSONL findings log
└── KILL # Kill switch
Extending MetaPWN
Plugin API
Drop a .py file into data/plugins/:
def register(reg):
@reg("Z", "My custom module")
def my_module(target, ctx):
# your logic here
print(f"target = {target}")
return NoneLoad plugins with:
MetaPWN› F1 # runs the plugin loader
Rule engine
Edit data/rules.json:
{
"rules": [
{
"if": "content contains 'password'",
"then": "alert possible secret leak"
},
{
"if": "header Server contains 'Apache/2.4.49'",
"then": "CVE-2021-41773"
}
]
}Scope control
Edit data/scope.txt:
allow: *.example.com, 10.0.0.0/8
deny: *.gov, 169.254.0.0/16
Kill switch
MetaPWN› F13 # toggle data/KILL
When data/KILL exists, modules stop executing.
Optional Dependencies
Check availability from inside MetaPWN:
MetaPWN› deps
MetaPWN› tools
Python libraries
aiohttp aiofiles beautifulsoup4 lxml requests PyPDF2 openpyxl
python-docx python-pptx olefile Pillow pyzbar timezonefinder pysmb
smbprotocol ssdeep tlsh msoffcrypto-tool python-magic pefile dnspython
pyOpenSSL cryptography yara-python ipwhois pytesseract svglib reportlab
icalendar vobject exifread hachoir pyasn1 pyasn1-modules pyyaml piexif
imagehash psd-tools
External tools
exiftool ffprobe ffmpeg mediainfo mkvinfo 7z unrar unzip zip tesseract
steghide binwalk foremost sleuthkit testdisk hashcat john hydra sqlmap
nmap dig whois curl wget git aria2c rclone smbclient snmpwalk lsusb
lspci dmidecode lsblk journalctl systemctl loginctl getcap lsof iw nmcli
bluetoothctl lpstat klist ldapsearch kubectl aws az gcloud
Safety Features
· Graceful shutdown — Ctrl+C writes a partial report before exit · Rate limiting — global token delay, per-request · HTTP cache — bounded LRU, avoids repeat requests · Cookie jar — Netscape format, auto-populated from responses · Scope file — allow / deny directives for safe-targeting · Kill switch — data/KILL file halts all module execution · Checkpointing — data/checkpoint.json for resumable runs · Session logging — data/logs/session_.log + data/metapwn.log · Artifact attribution — every generated file is recorded as a finding · Dependency-aware — modules detect missing libraries and degrade gracefully
Legal Notice
╔══════════════════════════════════════════════════════════════════════╗
║ AUTHORIZED USE ONLY ║
║ ║
║ MetaPWN is intended exclusively for: ║
║ ║
║ • Authorized red-team engagements with signed scope ║
║ • Penetration tests with written client permission ║
║ • Digital forensics & incident response on owned systems ║
║ • OSINT investigations on publicly available information ║
║ • Security research & education in isolated labs ║
║ ║
║ Unauthorized use against systems, networks, or data you do not ║
║ own or have explicit written permission to test is ILLEGAL and ║
║ may violate computer fraud, privacy, and telecommunication laws ║
║ in your jurisdiction. ║
║ ║
║ The author assumes NO liability for misuse, damages, or legal ║
║ consequences arising from use of this software. ║
╚══════════════════════════════════════════════════════════════════════╝
Credits
Tool MetaPWN Tagline Adversary Emulation & Metadata Intelligence Platform Author SYLHETYHACKVENGER Handle THE-ERROR808 Language Pure Python 3.9+ Pillars 46 (A → AT) Modules 600+
MetaPWN — Adversary Emulation & Metadata Intelligence Platform
Built for operators who need everything in one REPL.

