How it works
stng combines several extraction strategies:
- Scans bytes for printable ASCII and UTF-16LE runs.
- Recognizes Go and Rust runtime layouts, symbols, and x86/arm64 stack strings.
- Decodes Base64, Base32, Base85, hexadecimal, URL, and Unicode-escape text.
- Tests likely single-byte XOR keys and optional user-supplied keys.
- Uses Rizin or radare2, when installed, for deeper addresses and multi-byte XOR recovery.
- Classifies likely IOCs, commands, paths, credentials, tokens, and other security-relevant text while filtering common compiler noise.
What the filters mean
Default output aims to remain useful during triage. --interesting is more
selective; --unfiltered shows the raw/noisy candidates. Filtering changes
presentation, not the bytes being analyzed.
Cache behavior
stng does not cache extracted strings; extraction reruns on every call, and
tools embedding the library cache results themselves. The CLI caches only
optional Rizin/radare2 output, keyed by file content, for up to 30 days and
4096 files. Use --no-cache for one run or --flush-cache to discard the
target's cached Rizin analysis.
Results depend on the stng version, options, and optional Rizin/radare2 presence and version. Pin those inputs when comparing runs across systems.