Capture Reliable Screenshots from the Linux Command Line with scrot
You will finish with commands for capturing the whole X display, the focused window, or a mouse-selected region, with filenames that record when the image was made. The examples use scrot 1.10, installed here as Debian package 1.10-1build2. Allow about ten minutes if your X display is already working.
The route
Jump straight to the step you need, or tick off Done means at the end.
- 1. Check the installed command and display
- 2. Capture the full display with a timestamped name
- 3. Capture the focused window
- 4. Select a window or rectangle
- 5. Prevent an existing file from being replaced
- 6. Use quality, format and metadata deliberately
- 7. Add a safe post-capture action
- 8. Diagnose a failed capture
You need the scrot package, an active X display, and permission to write to the destination directory. This guide covers ordinary user commands. It does not need sudo: elevated privileges will not fix a missing display or make a screenshot safer.
1. Check the installed command and display
Start with read-only checks. scrot is an X screenshot utility, so a shell in a text-only session, a remote connection without X forwarding, or a Wayland-only desktop may not provide a usable display.
$ command -v scrot
/usr/bin/scrot
$ scrot --version
scrot version 1.10
$ printf 'display: %s\n' "${DISPLAY:-not set}"
display: :0
Your display value can differ. The important checkpoint is that command -v finds the intended binary and DISPLAY is set to the X display you intend to capture. To target another X display, use -D or --display, for example scrot --display :1. Do not guess a display number on a multi-user host.
2. Capture the full display with a timestamped name
With no selection option, scrot captures the display and saves an image. Give it a filename containing a strftime pattern so repeated captures do not collide:
$ mkdir -p "$HOME/Pictures/screenshots"
$ scrot "$HOME/Pictures/screenshots/%Y-%m-%d_%H-%M-%S.png"
$ ls -lh "$HOME/Pictures/screenshots/"
The filename is expanded when scrot runs. The .png suffix selects PNG, and the output is written under your home directory. A successful command normally prints nothing. The final listing should contain a new file such as 2026-09-26_14-30-00.png; the exact timestamp and size will differ.
Checkpoint: verify the image type without opening it:
$ file "$HOME/Pictures/screenshots/2026-09-26_14-30-00.png"
/home/you/Pictures/screenshots/2026-09-26_14-30-00.png: PNG image data, ...
Replace the example timestamp with the name that actually exists. The shell expands ~ in an unquoted word, but using "$HOME" keeps the path clear when it is combined with other text.
3. Capture the focused window
Use --focused when the target window is already active:
$ scrot --focused "$HOME/Pictures/screenshots/focused-%Y-%m-%d_%H-%M-%S.png"
$ file "$HOME/Pictures/screenshots/focused-2026-09-26_14-31-00.png"
/home/you/Pictures/screenshots/focused-2026-09-26_14-31-00.png: PNG image data, ...
The window must be focused at the instant scrot takes the shot. If you need to choose a window yourself, use interactive selection instead. Window decorations are not automatically implied by every selection: add --border when selecting a window and you also want the window manager border.
4. Select a window or rectangle
Run --select, then click a window or drag across a rectangle. Arrow keys can resize the selected rectangle:
$ scrot --select "$HOME/Pictures/screenshots/area-%Y-%m-%d_%H-%M-%S.png"
Selection is interactive, so keep the terminal available while you move the pointer. Press Escape to cancel. The default selection action captures the chosen area. For a visible countdown before selection, combine --delay with --count:
$ scrot --count --delay 5 --select "$HOME/Pictures/screenshots/area-%Y-%m-%d_%H-%M-%S.png"
5
4
3
2
1
If the delay must happen before you begin selecting, prefix the seconds with b, as in --delay b5. Without that prefix, the delay is applied before the capture after selection.
5. Prevent an existing file from being replaced
scrot does not overwrite the output file by default. That is a useful guard when a fixed filename is used:
$ scrot "$HOME/Pictures/screenshots/latest.png"
scrot reports that the destination exists and leaves the previous image in place.
The exact diagnostic text can vary with packaging. Use --overwrite only when replacing that exact file is intentional:
$ scrot --overwrite "$HOME/Pictures/screenshots/latest.png"
$ file "$HOME/Pictures/screenshots/latest.png"
/home/you/Pictures/screenshots/latest.png: PNG image data, ...
This is a destructive action for the previous screenshot. scrot does not provide an undo command. If the old image matters, copy it first, or use a timestamped filename and leave the old file untouched.
6. Use quality, format and metadata deliberately
The file extension normally selects the format. You can make the choice explicit with --format. Quality is numbered from 1 to 100 and defaults to 75, but its effect depends on the format:
$ scrot --format jpg --quality 90 "$HOME/Pictures/screenshots/review-%Y-%m-%d_%H-%M-%S.jpg"
$ file "$HOME/Pictures/screenshots/review-2026-09-26_14-35-00.jpg"
/home/you/Pictures/screenshots/review-2026-09-26_14-35-00.jpg: JPEG image data, ...
For lossless formats such as PNG, the quality setting is ignored. For JPEG, quality affects the result while compression is tied to it. scrot's default compression level is 7, but PNG quality is not a reason to change it. Keep PNG for text and interface screenshots when exact pixels matter; choose JPEG when a smaller, lossy file is acceptable.
To include the pointer, add --pointer. To produce a thumbnail beside the main image, add --thumb 25 for 25 percent of the full dimensions, or use an explicit size such as --thumb 320x240. The thumbnail name is available to an execution command through the $m special string.
7. Add a safe post-capture action
--exec runs a command after the image is saved. The $f special string expands to the saved image's full path. Quote the command as one shell argument, and do not put untrusted text into it:
$ scrot "$HOME/Pictures/screenshots/%Y-%m-%d_%H-%M-%S.png" \
--exec 'file "$f"'
/home/you/Pictures/screenshots/2026-09-26_14-36-00.png: PNG image data, ...
The command is useful for verification or a known local converter. It runs after capture, so a failure in the post-capture command does not mean that the screenshot itself was never written. Treat --exec as shell execution: avoid expanding data from filenames, window titles or other untrusted sources into a new command.
8. Diagnose a failed capture
If scrot cannot open the display, check DISPLAY, whether the session is X11, and whether the current user owns or can access that display. If the command reports that a file exists, choose a new name or make the replacement explicit with --overwrite. If selection does not appear, check that the command was started from the same graphical session and that another window is not holding the pointer or keyboard grab.
For a fixed window identifier, first obtain a valid X window ID with xwininfo, then pass it to --window. Do not paste a window title where an identifier is required. A capture of another user's display or window may expose private material and may be blocked by the X server; use only displays you are authorised to inspect.
Done means
scrot --versionreports the installed version and the intended X display is set.- A full-display, focused-window, or selected-area screenshot exists at the expected path.
fileconfirms the output format and the destination was not silently overwritten.- Timestamped names are used for repeatable captures, or
--overwritewas chosen knowingly. - Any
--execcommand is quoted, local, and safe to run against the saved image.