strings is one of the first commands worth running on almost any unfamiliar file in a CTF — it scans a file and prints every sequence of printable characters it finds, regardless of whether the file is a program, a memory dump, or something else entirely.
1. The baseline command
Run it directly against any file — no setup required, it's preinstalled on virtually every Linux system:
strings challenge.bin
Scroll (or pipe to less) through the output looking for anything that looks like a flag format, a URL, a file path, or a function/library name that hints at what the binary does.
2. Filtering straight to the flag format
Rather than reading the whole dump, grep directly for the competition's flag prefix:
strings challenge.bin | grep -i "flag{"
This single command catches a surprising number of beginner-level reversing and pwn challenges outright — always worth trying before any deeper analysis.
3. Catching wide-character (UTF-16) strings too
Windows binaries often store strings as UTF-16, which the default strings scan can miss entirely since it expects single-byte ASCII. The -el flag catches these:
strings -el challenge.exe
Run both the default scan and the -el variant on anything that looks like a Windows binary — between them they catch both common string encodings.
4. Setting a minimum length
Short printable sequences that happen to show up inside binary data create a lot of noise. Raising the minimum length filters most of that out:
strings -n 8 challenge.bin
Wrapping up
strings finds anything left in plain text — it finds nothing that was actually encoded, encrypted, or compressed, which is exactly when you need to move on to a real disassembler. See our Ghidra tutorial for that next step, and flag formats explained for what to grep for once you're scanning.