A large text file containing a huge amount of noise lines is provided. The grep command lets us search directly for the pattern picoCTF{ across all this content in a single command, without having to read the file manually.
| Platform | picoGym |
| Category | General Skills / Misc |
| Points | 50 pts |
| Difficulty | Beginner |
| Technique | Text search with grep |
The challenge provides an archive containing a large text file, file.txt, with several thousand lines of randomly generated content. The challenge's name — "First Grep" — clearly hints at the tool expected to solve it.
We download and open the file in a text editor to get a sense of it:
$ wc -l file.txt
118421 file.txt
Over 118,000 lines. Scanning it manually, line by line, to spot a specific string is simply impractical. We need a search tool.
The grep command (Global Regular Expression Print) searches for a pattern in a text file and only displays the lines that contain it. We search directly for the characteristic prefix of all picoCTF flags:
$ grep "picoCTF{" file.txt
The command returns almost instantly the one relevant line out of the 118,000:
a8f3k2j9x... picoCTF{***************************} ...m3n5p8q1
If the provided archive contains several files spread across subfolders rather than a single large file, the -r (recursive) option lets us apply the same search to the entire tree:
$ grep -r "picoCTF{" .
./data/part_042/chunk_17.txt:...picoCTF{***************************}...
This option is extremely useful outside of CTFs too — for example to quickly find a string across an entire codebase or a folder of logs.
A few grep options that come up constantly:
grep -o "picoCTF{.*}" — only prints the matching pattern (the part matched by the regular expression), not the whole line. Handy when the line has a lot of noise around the flaggrep -i — ignores case (upper/lowercase), useful when unsure of the exact formatgrep -n — prints the matching line number, handy for finding the context back in the original file$ grep -o "picoCTF{[^}]*}" file.txt
picoCTF{***************************}
The flag is deliberately hidden — follow the method, you've earned it. 💪
grep is probably the most used tool day-to-day in CTFs as well as system administration. Knowing how to search for a precise pattern in a large volume of text — logs, memory dumps, source code, network captures — is a non-negotiable base skill.
grep "pattern" file remains the fastest command to find a needle in a haystack of textgrep -r extends the search to entire folders, very useful when facing large archivesgrep -o and regular expressions let you extract exactly what you're looking for rather than the whole lineDiscuss this writeup with the community on the CTFdojo Discord.
Join the Discord →