strings(1) for malware analysis. stng finds plain, encoded and XOR-obfuscated
strings, understands Go and Rust binaries, and flags URLs, IPs, commands and
suspicious paths.
brew install atomdrift-project/tap/stng
# or, with Rust 1.94+ and a C compiler:
cargo install --git https://github.com/atomdrift-project/stngOptional: Rizin or radare2 finds more strings and enables --xorscan.
stng malware.bin # strings by section, XOR detection on
stng -i malware.bin # skip raw-scan noise
stng --json malware.bin # machine-readable output
stng --xor 0xAB malware.bin # decode with a known key (hex or text)
stng --xorscan malware.bin # slow multi-byte XOR searchstng = { git = "https://github.com/atomdrift-project/stng", default-features = false }let opts = stng::ExtractOptions::new(4).with_garbage_filter(true).with_xor(None);
for s in stng::extract_strings_with_options(&bytes, &opts) {
println!("{:#x} {:?} {}", s.data_offset, s.kind, s.value);
}default-features = false leaves out the CLI's dependencies.
