The strings Command for CTFs

Tool · Misc

strings is one of the first commands worth running on almost any unfamiliar file in a CTF — it scans a file and prints every sequence of printable characters it finds, regardless of whether the file is a program, a memory dump, or something else entirely.

1. The baseline command

Run it directly against any file — no setup required, it's preinstalled on virtually every Linux system:

strings challenge.bin

Scroll (or pipe to less) through the output looking for anything that looks like a flag format, a URL, a file path, or a function/library name that hints at what the binary does.

2. Filtering straight to the flag format

Rather than reading the whole dump, grep directly for the competition's flag prefix:

strings challenge.bin | grep -i "flag{"

This single command catches a surprising number of beginner-level reversing and pwn challenges outright — always worth trying before any deeper analysis.

3. Catching wide-character (UTF-16) strings too

Windows binaries often store strings as UTF-16, which the default strings scan can miss entirely since it expects single-byte ASCII. The -el flag catches these:

strings -el challenge.exe

Run both the default scan and the -el variant on anything that looks like a Windows binary — between them they catch both common string encodings.

4. Setting a minimum length

Short printable sequences that happen to show up inside binary data create a lot of noise. Raising the minimum length filters most of that out:

strings -n 8 challenge.bin

Wrapping up

strings finds anything left in plain text — it finds nothing that was actually encoded, encrypted, or compressed, which is exactly when you need to move on to a real disassembler. See our Ghidra tutorial for that next step, and flag formats explained for what to grep for once you're scanning.

← Back to Blog