Everything you need to know about FOCA: the metadata analysis tool

  • FOCA allows you to extract sensitive information from files on the web or locally.
  • The tool is ideal for pre-collection tasks in security audits.
  • It integrates multiple search engines and supports plugins to extend its functions.
  • Its Open Source version allows the community to adapt and improve its performance.

FOCA tool for metadata

Cybersecurity continues to evolve, and with it, the tools that allow for the effective protection and auditing of systems. One of the best-known tools in security auditing environments is FOCA , a solution geared towards the analysis and extraction of metadata from digital files.

Despite having been on the radar of professionals for over a decade, it continues to surprise with what it's capable of, especially when it comes to extracting sensitive information from seemingly innocuous documents.

But what makes FOCA so special? Beyond being a simple metadata extraction tool, it has become a complete suite for target identification in security audits. Its ability to analyze documents from the network or locally, its integration with other search engines, and its intuitive interface make it an essential solution.

What is FOCA and why is it so widely used?

FOCA is an acronym for Fingerprinting Organizations with Collected Archives . It is an open-source tool designed to extract and analyze metadata present in a wide variety of digital files. It was initially developed by Informática 64 (now ElevenPaths, part of Telefónica) and has been used for over a decade in auditing, forensics, and penetration testing environments.

Its essential function is to collect public files, primarily from websites, and extract the information hidden within them. This information may seem harmless, but it often reveals system users, internal configurations, software versions, and even network paths—all of which represent a potential entry point for an attacker.

On the other hand, what began as a utility limited to the metadata of office files, has evolved into a versatile tool for remotely fingerprinting organizational structures.

Using FOCA in safety audits

Main features of FOCA

What makes FOCA stand out from other similar solutions is its ability to automate complex data collection tasks . The most important features offered by this tool are detailed below:

  • Scanning public documents on the web: Use search engines like Google, Bing, and DuckDuckGo to locate files associated with a specific domain.
  • Deep metadata extraction: Detects embedded information in files such as Microsoft Office, Open Office, PDF, PS, EPS, SVG, images, and more.
  • Identification of sensitive data: User names, versions of the software used, source operating system, absolute paths, printers used or internal servers.
  • Network mapping: Allows you to find subdomains, perform DNS zone transfers, and create an organizational map of the target infrastructure.
  • IP and domain discovery: Through techniques such as PTR scanning, reverse IP lookup, DNS dictionary attacks and the use of well-known DNS records.

FOCA not only serves as a metadata extractor, but also allows the application of OSINT ( Open Source Intelligence ) techniques through its search capabilities and integration with APIs such as Shodan.

FOCA use cases in cybersecurity

The primary use of FOCA is during the initial phases of a security analysis or penetration test . This process is called footprinting , and its objective is to obtain as much information as possible about a target without directly interacting with it.

For example, by analyzing documents posted on a company's website, FOCA can extract:

  • The name of the person who created or edited the document.
  • Dates it was modified and printed.
  • Software used (Word 2016, Adobe Acrobat Pro, etc.).
  • Printers, absolute paths, operating systems, etc.

With all this data, the organization's technological environment , equipment, software, and even its internal structure can be inferred . All of this is achieved without deploying a single package to its servers, making FOCA especially effective for penetration testers and digital forensic analysts.

pentesting seal

How FOCA works step by step

Working with FOCA is relatively simple, even though the tool is in English. There are two ways to work with it: with local files on your own computer or with public files located on the Internet. Both methods are summarized below:

1. Analysis of local files

With the tool open, simply go to the “Metadata” section , right-click, and select “Add file” (or “Add folder” if you want to analyze an entire folder). You can also drag and drop documents directly.

Once loaded, select the files, right-click, and choose “Extract Metadata” . FOCA will then display all the metadata found, organized by file.

2. Online file analysis

This is the most powerful procedure. You should start by creating a new project, specifying the project name , the domain of the website to be analyzed, and optionally a destination folder for the downloaded documents.

Once configured, FOCA will search for files using Google, Bing, and/or DuckDuckGo, and also allows you to filter by file type (PDF, DOCX, XLSX, etc.). Once documents are located, they can be downloaded and their metadata extracted, just like local files.

Technical requirements to use FOCA

FOCA is designed to run on Windows (versions 7 and later, 64-bit) and requires some additional components:

  • . NET Framework 4.7.1 or higher.
  • Visual C++ Redistributable 2010 x64 or later.
  • SQL Server 2014 or higher, since FOCA uses a database to store project data.

During installation, if an available instance of SQL Server is not detected, the user will be prompted to enter a connection string manually.

Thanks to the refactoring work carried out by the ElevenPaths team , FOCA is now more stable and efficient, even allowing multi-threaded operations with a task queue optimized for large volumes of data.

Over the years, FOCA has established itself as one of the most versatile and powerful tools for metadata analysis and public information gathering . Its ability to obtain vital data from open sources without direct intervention makes it indispensable in any digital audit or forensic analysis.


Add as preferred source in Google