STRACE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
strace traces system calls and signals. Essential for debugging and understanding program behavior.
BASIC USAGE#
strace command # Trace command strace -p PID # Attach to running process strace -f command # Follow forks (child processes) strace -o file.txt command # Output to file
OUTPUT OPTIONS#
strace -o output.txt command # Save to file strace -o output.txt -ff command # Separate file per process strace -t command # Print timestamp strace -tt command # Microsecond timestamp strace -T command # Show syscall duration strace -r command # Relative timestamp strace -c command # Statistics summary strace -C command # Stats + regular output
FILTERING SYSTEM CALLS#
strace -e trace=open command # Only 'open' syscalls strace -e open command # Shorthand strace -e trace=read,write cmd # Multiple syscalls strace -e trace=file command # File operations strace -e trace=network cmd # Network operations strace -e trace=process cmd # Process operations strace -e trace=memory cmd # Memory operations strace -e trace=signal cmd # Signal operations strace -e trace=ipc cmd # IPC operations strace -e trace=desc cmd # File descriptor operations # Exclude syscalls strace -e trace=\!open command # All except 'open'
TRACE CATEGORIES#
file open, stat, chmod, chown, etc. process fork, exec, wait, etc. network socket, connect, send, recv, etc. signal signal, sigaction, kill, etc. ipc msg*, sem*, shm* desc read, write, close, dup, etc. memory mmap, mprotect, brk, etc. %file Same as file %process Same as process %network Same as network
STRING AND SIZE OPTIONS#
strace -s 100 command # String size (default: 32) strace -s 1000 command # Larger strings strace -x command # Hex output for non-ASCII strace -xx command # Hex for all strings
FOLLOW OPTIONS#
strace -f command # Follow forks strace -ff -o out command # Separate file per PID strace -F command # Follow vfork
ATTACHING TO PROCESSES#
strace -p 1234 # Attach to PID strace -p 1234 -p 5678 # Multiple PIDs strace -p $(pgrep nginx) # By process name # Ctrl+C to detach
COMMON EXAMPLES#
# Debug program startup strace ./program # Find config files being read strace -e open,openat ./program 2>&1 | grep -E '\.conf|\.cfg|\.ini' # Find files program accesses strace -e trace=file ./program 2>&1 # Network activity strace -e trace=network ./program # Why program is slow strace -T ./program 2>&1 | sort -t= -k2 -n # Count syscalls strace -c ./program # Debug library loading strace -e trace=open ./program 2>&1 | grep '\.so' # Find why program fails strace -e trace=file ./failing_program # Watch file access in real-time strace -e trace=file -p $(pgrep apache2) # Debug DNS issues strace -e trace=network -s 1000 host example.com
SECURITY/FORENSICS#
# What files a process opens strace -e open,openat -p PID # Network connections strace -e connect,socket -p PID # What a script writes strace -e write -s 1000 ./script.sh # Check for suspicious behavior strace -f -e trace=execve,connect,open ./suspicious
OUTPUT INTERPRETATION#
# Successful call
open("/etc/passwd", O_RDONLY) = 3
# Failed call
open("/nonexistent", O_RDONLY) = -1 ENOENT (No such file or directory)
# Common return values:
# = N Success, N is return value (often file descriptor)
# = -1 Failure (check error code)
# = 0 Success or EOF
# Common errors:
# ENOENT No such file or directory
# EACCES Permission denied
# EEXIST File exists
# EPERM Operation not permitted
# EAGAIN Resource temporarily unavailable
# EINTR Interrupted system call
PERFORMANCE ANALYSIS#
# Time spent in syscalls
strace -c ./program
# Shows: % time, seconds, calls, errors, syscall
# Find slow syscalls
strace -T ./program 2>&1 | awk -F'[<>]' '{print $2, $0}' | sort -n
# Identify blocking calls
strace -T -e read,write,poll,select ./program
DEBUGGING SPECIFIC ISSUES#
# Why can't find library strace -e open ./program 2>&1 | grep '\.so' # Why permission denied strace -e open,stat,access ./program 2>&1 | grep -i denied # Why hanging strace -p PID # Look for blocking calls: read, poll, select, futex # Why high CPU strace -c -p PID # Run for a while, Ctrl+C to see summary # Debug shell script strace -f -e execve /bin/bash script.sh
ALTERNATIVES#
ltrace # Library call tracer dtrace # Dynamic tracing (Solaris, macOS) perf trace # Linux perf based tracing bpftrace # eBPF based tracing
USEFUL PATTERNS#
# All file opens strace -e openat 2>&1 | grep -v ENOENT # Writes to specific file strace -e write -p PID 2>&1 | grep 'write(3,' # fd 3 # Follow entire process tree strace -ff -o /tmp/trace ./program # Creates /tmp/trace.PID for each process # Time analysis strace -ttt -T -o trace.log ./program # Then analyze with awk/grep
QUICK REFERENCE#
strace command Basic trace strace -p PID Attach to process strace -f command Follow forks strace -o file command Output to file strace -c command Statistics only strace -e open command Filter syscalls strace -e trace=file cmd Category filter strace -T command Show time per call strace -t command Timestamps strace -s 200 command Longer strings