Skip to content

Binwalk

Firmware and container analysis by signature scanning

CommunityForensics· Firmware & ContainersIntermediateOpen sourceEntry revised 15 Dec 2025
  • Linux
  • macOS
  • Source

Community. Contributor-submitted. Not every claim has been re-checked. Cross-check against the upstream documentation before relying on a command.

This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

4 commands documented

Binwalk scans a binary for embedded file signatures — squashfs, JFFS2, UBI, LZMA, certificates, PNG blocks — and can extract what it finds so a filesystem can be inspected. It is how firmware images become directories.

Older versions depended on external utilities for each extraction; modern releases do much of it internally but still benefit from helper packages being installed.

Supported platforms

3

Documented install or usage guidance

Learning curve

intermediate

Difficulty of becoming productive, not of the underlying theory

Tags

firmware, extraction, carving, entropy, containers

Dataset entry

binwalk.ts

Reviewed 2025-12-15

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

RecommendedHomebrew
brew install binwalk
  • Install the optional helpers it lists (`sasquatch`, `unshield`, `lzo`, `cmake`) if you expect vendor compressions.

Package availability follows your distribution and enabled repositories. Entry revised 15 Dec 2025 — confirm the current release on the project's own download page.

Commands

4 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Identify what is inside

bash

Signature scan with offsets, which is usually the whole first step.

binwalk router-fw.bin

02Extract recursively

bash

Carves found filesystems into a directory tree and repeats until nothing more is recognised.

binwalk -Me router-fw.bin
  • Extracted firmware may contain setuid binaries, scripts with default credentials and vendor code under licence. Keep it in the lab folder.

Notes

  • `-M` recurses, `-e` extracts, `--directory=out` keeps the tree tidy, `-y` overwrites without asking.

03Read the entropy graph

bash

Shows high-entropy (compressed or encrypted) regions versus flat areas — the quickest way to know whether extraction will even work.

binwalk -B -t 20 router-fw.bin

Example output

Illustrative only — real output depends on the target, version and your position on the network.

DECIMAL       HEXADECIMAL     ENTROPY
0             0x0             0.112 [weak]
65536         0x10000         7.988 [strong]

Notes

  • `-B`/`--centralize` prints a numeric entropy report instead of a graph.

04Diff two firmware revisions

bash

Compare extracted trees to see what a vendor actually changed between builds.

diff -rq _v1.extracted/squashfs-root _v2.extracted/squashfs-root | head -50

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

'Extraction is unavailable for one or more file types'Cause 1/2

Possible causes

  • Missing external utilities for that compression/container.

Usual fix

Install the helper packages the error names, or extract that region manually with `dd` at the reported offset plus the specific tool.

dd if=router-fw.bin bs=1 skip=1048576 of=root.sqsh
unsquashfs -d root root.sqsh
Everything is high entropy, nothing extractsCause 2/2

Possible causes

  • The image is encrypted or the container has a header Binwalk does not know.

Usual fix

Treat that as a finding about the device's design. Look for a decryption key in a related partition or in the vendor's update package rather than forcing extraction.

Tips

  • Keep the original file unchanged; always work from a copy in an extracted directory.
  • `--exclude-binwalk` avoids noise from files that merely contain signatures.

Alternatives & comparisons

Not documented yet: 7z, jefferson, sasquatch. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Forensics