PicoCTF First Grep Writeup — Find a Flag with grep

Misc 2026-11-23 · picoGym · By CTFdojo · ⏱ ... · 👁 ... views
𝕏 Share
TL;DR

A large text file containing a huge amount of noise lines is provided. The grep command lets us search directly for the pattern picoCTF{ across all this content in a single command, without having to read the file manually.

PlatformpicoGym
CategoryGeneral Skills / Misc
Points50 pts
DifficultyBeginner
TechniqueText search with grep

Challenge description

The challenge provides an archive containing a large text file, file.txt, with several thousand lines of randomly generated content. The challenge's name — "First Grep" — clearly hints at the tool expected to solve it.

Step 1 — Observe the problem

We download and open the file in a text editor to get a sense of it:

$ wc -l file.txt
118421 file.txt

Over 118,000 lines. Scanning it manually, line by line, to spot a specific string is simply impractical. We need a search tool.

Step 2 — Use grep

The grep command (Global Regular Expression Print) searches for a pattern in a text file and only displays the lines that contain it. We search directly for the characteristic prefix of all picoCTF flags:

$ grep "picoCTF{" file.txt

The command returns almost instantly the one relevant line out of the 118,000:

a8f3k2j9x... picoCTF{***************************} ...m3n5p8q1

Step 3 — The case of a whole folder

If the provided archive contains several files spread across subfolders rather than a single large file, the -r (recursive) option lets us apply the same search to the entire tree:

$ grep -r "picoCTF{" .
./data/part_042/chunk_17.txt:...picoCTF{***************************}...

This option is extremely useful outside of CTFs too — for example to quickly find a string across an entire codebase or a folder of logs.

Useful variants

A few grep options that come up constantly:

$ grep -o "picoCTF{[^}]*}" file.txt
picoCTF{***************************}
🚩 picoCTF{flag intentionally hidden}

The flag is deliberately hidden — follow the method, you've earned it. 💪

Key takeaways

grep is probably the most used tool day-to-day in CTFs as well as system administration. Knowing how to search for a precise pattern in a large volume of text — logs, memory dumps, source code, network captures — is a non-negotiable base skill.

Resources

CTFdojo
CTFdojo
Community of ethical hackers writing beginner-friendly CTF writeups and guides.

Got a question or a different approach?

Discuss this writeup with the community on the CTFdojo Discord.

Join the Discord →