Home / Alt manpages / llvm-strings-20(1)

  • llvm-strings-20(1)
  • User command
  • linux

Find Printable Text in Binaries with llvm-strings-20

You will use llvm-strings-20 to extract readable ASCII sequences from a binary or other file, then narrow the result with a minimum length or add file offsets. The command only reads its inputs and writes matches to standard output. Allow about ten minutes for a first inspection.

1. Check the installed tool

This guide targets the Ubuntu LLVM package installed on this machine: llvm-20, version 20.1.8. The version matters because command-line tools can gain or change options between LLVM releases. Check the executable before relying on an example:

$ command -v llvm-strings-20
/usr/bin/llvm-strings-20
$ llvm-strings-20 --version
llvm-strings-20
Ubuntu LLVM version 20.1.8
  Optimized build.

If the first command prints nothing, install the package through your normal system administration process. That is the only point at which elevated privileges might be needed. Running the scanner itself should normally be unprivileged, provided you can read the input.

2. Scan a file with the default threshold

Pass a file path after the options. By default, a match is a run of at least four printable ASCII characters. A newline or any other non-printable byte ends the run, so this is a quick way to spot embedded names, messages, paths and format markers:

$ llvm-strings-20 /path/to/program
ELF
libc.so.6
GLIBC_2.34
Usage: program [options]
error: configuration file not found

The output is not a decoded view of the file. It is a list of byte sequences that happen to meet the printable-character rule. A line may be padding, metadata, a symbol name or an accidental run in compressed or encrypted data. Treat matches as clues and verify any finding with a format-aware tool.

For a quick, reproducible check, standard input works too:

$ printf 'no\nABCD\nefghij\n' | llvm-strings-20
ABCD
efghij

No input path, or an explicit - input, makes the program read standard input. This is useful in a pipeline, but it is also an easy distraction: if a command appears to wait, it may be waiting for terminal input. Supply a file or finish the pipeline rather than pressing random keys.

Checkpoint: the basic scan

  • llvm-strings-20 --version reports the expected installed release.
  • The input path is readable and the command exits successfully.
  • You understand that the output is printable ASCII evidence, not a complete interpretation of the file.

3. Change the minimum string length

Short matches create noise in many binaries. Set the minimum number of printable ASCII characters with -n or its long form --bytes. The value is a length, not a byte offset:

$ llvm-strings-20 --bytes=8 /path/to/program
$ llvm-strings-20 -n 12 /path/to/program

Use a larger threshold when you want likely messages or identifiers. Use a smaller one when searching for short format markers, but expect more incidental output. The default is four characters; it is not inferred from the file type.

Verify a threshold against known input before applying it to a large file:

$ printf 'abc\nABCD\nefghij\n' | llvm-strings-20 -n 3
abc
ABCD
efghij

There is no need to use sudo for this operation. If access fails, check the path and permissions first:

$ ls -l /path/to/program
$ test -r /path/to/program && echo readable || echo not-readable

4. Add file names or offsets to the evidence

When comparing more than one input, -f or --print-file-name prefixes every match with its containing file. This prevents output from several files becoming one ambiguous list:

$ llvm-strings-20 --print-file-name /path/to/first.bin /path/to/second.bin
/path/to/first.bin: configuration
/path/to/second.bin: configuration

To locate a match within one file, request an offset with -t or --radix. The accepted radix values are o for octal, d for decimal and x for hexadecimal:

$ llvm-strings-20 --radix=x /path/to/program
    22c configuration
    31a error: configuration file not found

The offset is useful for a follow-up inspection, but do not treat it as a line number. It is a byte position in the input as reported by this tool. Recheck the same file if it changes, and keep the radix visible in notes or scripts so a decimal and hexadecimal offset are not confused.

5. Handle output and failure safely

llvm-strings-20 does not modify an input file. Redirection can still overwrite an existing output before the scan starts, because the shell opens the destination first. Choose a new name, or use a backup you have deliberately made:

$ llvm-strings-20 -n 8 /path/to/program > /path/to/program.strings.new
$ test -s /path/to/program.strings.new && mv /path/to/program.strings.new /path/to/program.strings

The mv command above changes the destination name only after a non-empty result. It does not prove that the matches are meaningful, so inspect the file before treating it as an answer. If the scan fails, remove the explicitly named temporary file after checking that it is the one created by this command:

$ rm -- /path/to/program.strings.new

That removal is irreversible. Do not run it as a blind cleanup command, and do not delete the original binary to make room for scan output.

A non-zero exit status indicates an error. Common causes are an unreadable path, a missing input, an invalid option, or a broken pipeline. Capture the status in a script if later steps must not run after a failed scan:

$ if llvm-strings-20 /path/to/program > /tmp/program.strings; then
>     echo "scan completed"
> else
>     status=$?
>     echo "scan failed with status $status" >&2
> fi

6. Keep the result in proportion

The GNU-compatible -a or --all option is accepted but silently ignored. It does not switch on a hidden mode. LLVM's implementation scans the entire input file regardless of file format, unlike GNU strings, which can restrict its search to selected object-file sections. This difference can produce more output than expected.

Do not use this command as a malware verdict, a secret detector with guaranteed coverage, or a substitute for a parser. Printable text can be absent from a compressed or encrypted file, and a match can be deliberately planted. Preserve the original input, record the exact command and threshold, and use a format-aware or forensic tool for the next decision.

Done means

  • You confirmed the installed llvm-strings-20 version.
  • You scanned the intended file or pipeline and kept the input unchanged.
  • You chose the minimum length deliberately instead of assuming the default was automatic.
  • You used file names or an explicit radix when comparing or locating matches.
  • You checked the exit status and treated strings as leads for further verification, not proof by themselves.