Homebrew
RecommendedHomebrewbrew install binwalk
- Install the optional helpers it lists (`sasquatch`, `unshield`, `lzo`, `cmake`) if you expect vendor compressions.
Firmware and container analysis by signature scanning
Community. Contributor-submitted. Not every claim has been re-checked. Cross-check against the upstream documentation before relying on a command.
Binwalk scans a binary for embedded file signatures — squashfs, JFFS2, UBI, LZMA, certificates, PNG blocks — and can extract what it finds so a filesystem can be inspected. It is how firmware images become directories.
Older versions depended on external utilities for each extraction; modern releases do much of it internally but still benefit from helper packages being installed.
Supported platforms
3
Documented install or usage guidance
Learning curve
intermediate
Difficulty of becoming productive, not of the underlying theory
Tags
firmware, extraction, carving, entropy, containers
Dataset entry
binwalk.ts
Reviewed 2025-12-15
Grouped by platform. Elevation requirements are marked per method.
brew install binwalk
Needs elevated privileges (sudo / Administrator).
sudo apt install binwalk
pipx install binwalk
Package availability follows your distribution and enabled repositories. Entry revised 15 Dec 2025 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
Signature scan with offsets, which is usually the whole first step.
binwalk router-fw.bin
Carves found filesystems into a directory tree and repeats until nothing more is recognised.
binwalk -Me router-fw.bin
Notes
Shows high-entropy (compressed or encrypted) regions versus flat areas — the quickest way to know whether extraction will even work.
binwalk -B -t 20 router-fw.bin
Example output
Illustrative only — real output depends on the target, version and your position on the network.
DECIMAL HEXADECIMAL ENTROPY 0 0x0 0.112 [weak] 65536 0x10000 7.988 [strong]
Notes
Compare extracted trees to see what a vendor actually changed between builds.
diff -rq _v1.extracted/squashfs-root _v2.extracted/squashfs-root | head -50
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
Install the helper packages the error names, or extract that region manually with `dd` at the reported offset plus the specific tool.
dd if=router-fw.bin bs=1 skip=1048576 of=root.sqsh
unsquashfs -d root root.sqsh
Possible causes
Usual fix
Treat that as a finding about the device's design. Look for a decryption key in a related partition or in the vendor's update package rather than forcing extraction.
Not documented yet: 7z, jefferson, sasquatch. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.